Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
<strong>CanSecWest</strong>2007<br />
6<br />
IR: Current Process<br />
• Currently there are two main states<br />
a system could be in at IR time.<br />
• “Dead” System<br />
– Duplicate drives (non-volatile stores)<br />
• “Live” System<br />
–?<br />
Arrive on<br />
Scene<br />
Is System<br />
On?<br />
?<br />
Yes<br />
No<br />
Seize System<br />
/ Copy Drive<br />
VIDAS