July 2006 Archives

Reconstructing a Binary (4)

Reassembling a binary from a memory dump can be a tedious task. Now Harlan Carvey has released a Perl script which automates the process.

The Sleuth Kit v.2.05

Version 2.05 of the Sleuth Kit has been released. It now supports NTFS compression for files and folders.

Finding Network Socket Activity in Pools

I've got some questions regarding my IMF paper. So I decided to provide a use-case for an analysis based on pool allocations. This will reveal TCP/IP sockets in listening state and also network connections.

POOL_HEADER

| 2 Comments

This article introduces a small, yet important data structure of the Microsoft Windows NT kernel, the POOL_HEADER. For sure I will rely on this structure on several occasions. Also my talk at the IMF 2006 conference will be dedicated to it.

IMF 2006 Paper

My paper for the IMF 2006 conference in Stuttgart has been accepted. It is entitled Pool Allocations as an Information Source in Windows Memory Forensics.

Linux Memory Analysis

In his master thesis Jorge M. Urrea-Civilian examines data structures of the Linux 2.6 series kernel. He describes how the virtual address space of a process can be reconstructed from a swap file and the physical memory. The thesis might become the foundation of tools to analyze a Linux memory dump.

An EXE Template and the Rich Header

Peter Kankowski has released an improved template for EXE- files to be used with Sweetscape's 010 Editor. This template also allows to parse 64bit binaries. For the first time the template recognizes the "Rich" header inserted into binaries by Microsoft's linkers.

All about Write Blockers

In his presentation at the Techno Security 2006 conference Robert Botchek summarizes the basics of write blockers. The speaker is president of Tableau, LLC, a manufacturer of write blocking devices.

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12