Memory analysis
Dating the execution of certain routines
In an earlier article I discussed timestamps in thread and process objects. In this post I'll show how this information can be used to narrow in on the time a certain routine was executed at.
« December 2005 | Main | March 2006 »
Memory analysis
In an earlier article I discussed timestamps in thread and process objects. In this post I'll show how this information can be used to narrow in on the time a certain routine was executed at.
Side notes
Finally digital forensics has got a Wiki of its own, Simson Garfinkel set it up recently. Until now about 70 authors registered and created just under 40 pages. To make the Wiki grow Garfinkel asks the forensic community for contributions.
Memory analysis
To search memory images for processes and threads I resort on a structure named _DISPATCHER_HEADER. This article provides you with a summary of the relevant information.
Network forensics
In his presentation Yann Berthier introduces Netflows as an information source for network forensics.
Memory analysis
During the last weeks I've documented _EPROCESS and _ETHREAD structures for several versions of Microsoft Windows in the main (that is German) section of this blog. The declarations are in English anyway. I'd like to avoid duplicating those long lists here for several reasons, penalties by search engines among them. This post will guide you to the relevant articles. If there are still questions left please do not hestiate to ask me.
Lab
Lab
This blog is a project of
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
Germany
impressum@forensikblog.de
Copyright © 2005-2010 by
Andreas Schuster
All rights reserved.