Memory analysis
Memory Analysis Summary
Harlan Carvey has posted a great summary article on Windows memory analysis. In fact it is a free sample chapter from his new book on Windows Forensic Analysis.
« March 2007 | Main | May 2007 »
Memory analysis
Harlan Carvey has posted a great summary article on Windows memory analysis. In fact it is a free sample chapter from his new book on Windows Forensic Analysis.
Lab
Version 3.8.0 of FTimes has been released on SourceForge. This version adds support for SHA-256 hashes and some file systems, UDF among them. It also adds some more tools. Complete information is available from the changelog.
Memory analysis
Brendan Dolan-Gavitt wrote in and pointed me to his fine collection of XMagic definitions. With the help of these patterns and a config file (Brendan provides a sample) FTimes can pull some information about processes from a memory dump.
Side notes
The 2nd Annual Workshop on Digital Forensics & Incident Analysis will take place from 27-28 August 2007, at Samos, Greece. The CfP will close on 30th of April. The workshop proceedings will be published by IEEE Computer Society Press. Additional information is available at the conference website.
NT event log
GrokEVT is a set of Python scripts for reading Windows Event Log files (.evt) on Unix hosts. New in version 0.4.0 is grokevt-findlogs which carves event records from raw binary data like unallocated clusters or a memory dump.
Carving
One of the problems in file carving is to properly identify the borders of the former files. This especially holds true in case of fragmentation. In their submission to the DFRWS 2006 challenge Klayton Monroe and Jay Smith of KoreLogic Security and Andy Bair of MITRE (at that time) calculate the block-wise entropy to detect file boundaries and identify blocks which are unlikely to belong to a carved file.
Lab
Version 2.08 of The Sleuth Kit has been released. AFFlib now can be compiled in the Cygwin environment. The hfind tools to search hash sets now is also available for the Microsoft Windows platform. As usual the changelog provides a complete overview over bug fixes and API changes.
Library
The Spring 2007 issue of the International Journal of Digital Evidence (IJDE) was just published.
Memory analysis
GMG Systems, Inc. now offers KnTTools and KnTList to a limited group of prospective buyers.
Library
One of the few books that really helped me to get into Windows memory analysis is "Undocumented Windows 2000 Secrets" by Sven B. Schreiber. Unfortunately the book is out of print for some time. A few used copies are sold at Amazon and other internet marketplaces - at prices so high that I'm considering to invest in books instead of shares.
Fortunately Sven is so kind to provide an electronic edition of his work as a set of PDF files free of charge at his web site. Thank you very much, Sven!
This blog is a project of
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
Germany
impressum@forensikblog.de
Copyright © 2005-2010 by
Andreas Schuster
All rights reserved.