« October 2007 | Main | December 2007 »

Memory analysis

PTFinder Version 0.3.05

I'm excited to release version 0.3.05 of PTFinder to the public. This version fixes an endianess issue. It provides support for dumps that where obtained while under the effect of the Intel Physical Address Extension (PAE). Also there's a ready-to-run binary available for the Microsoft Windows platform.

(more...)

Memory analysis

Carving MFT Entries from Memory Images

Lance Mueller has released an EnScript that searches a memory dump for MFT entries.

(more...)

Side notes

Blog about EnScript

Guidance Software's EnCase provides the forensic examiner with a powerful scripting language, called EnScript. Beside the vendor-operated fora there's not much information about EnScript circulating in the net. A blog by Lance Mueller fills some need here.

(more...)

Side notes

Live-response on SUN Solaris

Evtim Batchev of SUN Iberia presented about live-response on the SUN Solaris platform at the 22nd TF-CSIRT meeting. His slides cover several data structures of the Solaris kernel and how they can be used in an examination of a running system.

Library

IJDE Fall 2007 Issue

The Fall 2007 issue of the International Journal of Digital Evidence (IJDE) has been posted. This issue contains three articles.

(more...)

Memory analysis

Catalogue of Kernel-mode Backdoors

Some time ago Skape and Skywing have published a Catalogue of Windows Kernel-mode Backdoor Techniques.

(more...)

Memory analysis

PoolTools Version 1.3.0

I have overhauled PoolFinder and the accompanying tools. The tools now use a SQLite data base instead of flat files for exachanging data. An experimental package now provides stand-alone versions of the tools, along with an embedded Perl interpreter.

(more...)