February 2008 Archives
Crash Dumps of 32bit and 64bit versions of Microsoft Windows differ significantly. Because the market share of 64bit machines increases steadily, I decided to update my post on the Crash Dump (DMP) format.
Matthieu Suiche and Nicolas Ruff have just released their first public version of the Sandman Framework.
Cutting the power or forcing a reset may not look like being proper procedures to preserve a computer's main memory. However, current research tells a different and fascinating story.
Brendan Dolan-Gavitt describes in a detailed blog post , how to find and how to interpret information about registry hives in memory images.
FireWire provides a simple and reliable means to image another computer's main memory. In this article I'll briefly talk about the history of direct memory access through FireWire. Also I will explain how to acquire a RAM image using the Helix boot CD.
