13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CanSecWest</strong>2007<br />

6<br />

IR: Current Process<br />

• Currently there are two main states<br />

a system could be in at IR time.<br />

• “Dead” System<br />

– Duplicate drives (non-volatile stores)<br />

• “Live” System<br />

–?<br />

Arrive on<br />

Scene<br />

Is System<br />

On?<br />

?<br />

Yes<br />

No<br />

Seize System<br />

/ Copy Drive<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!