April 2006 Archives

Data Lifetime

I was quite surprised to actually see parts of the main memory survive a reboot for the first time. Well, Farmer and Venema were not the first to describe this. Here are two more interesting papers on that topic.

Reconstructing a Binary (2)

If you followed through the first part of this tutorial, you might wonder if there shouldn't be a simpler way to extract the binary. Of course there is one.

New Tools

Over the weekend Harlan Carvey has released two tools to analyze full memory dumps of computers running Microsoft Windows 2000.

TULP2G version 1.3.0.3

| 1 TrackBack

The Netherlands Forensic Institute has just released a new version of TULP2G. This program acquires and analyzes data from mobile phones.

Persistance Through the Boot Process

In their book Forensic Discover Dan Farmer and Wietse Venema talk about the persistence of information in the main memory. However I haven't seen traces of a process surviving a reboot - until I analyzed the images of the DFRWS Memory Analysis Challenge.

Reconstructing a Binary (1)

It is possible to reconstruct the program binary of process from a memory dump. This enables you to scan a binary for viruses even if it has been deleted from the disk. This article outlines the process.

Reconstructing the Process Memory

For certain examinations it might be helpful to be able to extract the memory of a single process from the full dump. If the dump was obtained with "dd" the reconstruction of the process' memory is quite simple.

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12