Microsoft Kernel Memory Space Analyzer

Microsoft has just released version 8.1 of its Kernel Memory Space Analyzers to the public. This program provides a lot help when analyzing Windows memory dumps in DMP format.

(more...)

Problem when Dumping Memory over FireWire

Arne Vidstrom explains how dumping a PC's main memory over FireWire could cause the Memory Controller Hub of an Intel chipset to hang.

(more...)

PTFinder Version 0.3.00

Version 0.3.00 of PTFinder has been released. This version adds some experimental support for XML output.

(more...)

PTfinder Collection posted

I have posted a collection of PTfinders for Windows 2000, Windows XP (should be good for XP SP1 too), Windows XP SP2 and Windows Server 2003. I wish to thank reader "Frank" for his support. Please report bugs to bugs-ptfinder [at] forensikblog.de.

(more...)

Authenticating a Reconstructed Binary

As previously noted, a binary reconstructed from a memory dump may not match with the original file on disk. This raises the question how hash creation and file authentication procedures must be changed in order to provide this functionality.

(more...)

Detecting a Library Injection with FATKit

In a white paper AAron Walters describes how the Forensic Analysis ToolKits (FATKit) can be used to detect the injection of malicious code.

(more...)

Reconstructing a Binary (4)

Reassembling a binary from a memory dump can be a tedious task. Now Harlan Carvey has released a Perl script which automates the process.

(more...)

Reconstructing a Binary (4)

Reassembling a binary from a memory dump can be a tedious task. Now Harlan Carvey has released a Perl script which automates the process.

(more...)

Finding Network Socket Activity in Pools

I've got some questions regarding my IMF paper. So I decided to provide a use-case for an analysis based on pool allocations. This will reveal TCP/IP sockets in listening state and also network connections.

(more...)

POOL_HEADER

This article introduces a small, yet important data structure of the Microsoft Windows NT kernel, the POOL_HEADER. For sure I will rely on this structure on several occasions. Also my talk at the IMF 2006 conference will be dedicated to it.

(more...)
<< 1 2 3 4 5 6 7 8 9 10 >>