Blogs about: Memory Forensics

Featured Blog

Direct Memory Access is evil!

SebastianB wrote 2 months ago: Hello, Everybody should know that DMA is evil since the first Firewire Exploit was released arround … more →

Tags: Miscellaneous, DMA exploitation, FDE, firewire, full disk encryption, Git, Inception, MacPorts, Raspberry Pi

Memory Forensics (Searching Cryptography Keys in RAM)

thilaknath wrote 5 months ago: Have you ever wondered what would happen, when you are a forensic and in a position where u could no … more →

Tags: Inforamtion System Security, Inception, truecrypt, Volatility

hashdays 2012 - Security-Konferenzbericht1 comment

Peter Haag wrote 5 months ago: Vom 31. Oktober bis 3. November fanden dieses Jahr wieder die Hashdays statt. Es war die dritte Aufl … more →

Tags: malware, Conferences, Mobile Security, hashdays, Heap Visualization, malware analyse

Retrieving Digital Evidence: Methods, Techniques and Issues3 comments

belkasoft wrote 10 months ago: by Yuri Gubanov yug@belkasoft.com Belkasoft Ltd. http://belkasoft.com Abstract This article describe … more →

Tags: Methodology, Data recovery, Forensic Methodology, data recovery, evidence collection

Browser Cache

cyber0ximoron wrote 1 year ago: Hi, Recently I worked  on a forensic case which was not much challenging on technical areas though, … more →

Tags: Digital Forensic, Browser Cache, Password Recovery, IE cache, nirsoft

March for HTCIA: Chapter meetings and other notable events

htcia wrote 1 year ago: Whether you’re local to our chapters or traveling to their cities, we welcome your participati … more →

Tags: Chapter News, Mobile Device Forensics, Guidance Software, David Nardoni, SANS COINS, EnCase 7, proposed Bill C-30, Electronic Crimes Task Force, computer registry analysis

Hakin9 Magazine Features "Pulling Passwords from Memory Dump" Article2 comments

D. Dieterle wrote 1 year ago: Hakin9 is well known in the security circles and is just a great magazine. It is known as “A m … more →

Tags: Computer Security, cyber security, hakin9, IT Security, Computer Forensics, Computer Magazine, Software Exploits, Buffer Overflow

pull passwords from a memory dump

iuzumaki wrote 1 year ago: Several programs exist for memory analysis, here we will be using “Volatility” from Volatile Systems … more →

Tags: memory dumo, hivelist, sam keys, ntlm hash, password crack

Memory Forensics: Pull Process & Network Connections from a Memory Dump8 comments

D. Dieterle wrote 1 year ago: In the previous article, we learned how to pull passwords from a memory dump file. This time, we wil … more →

Tags: Computer Security, cyber security, Microsoft Windows, malware analysis, Memory Dumper

Memory Forensics: How to Pull Passwords from a Memory Dump14 comments

D. Dieterle wrote 1 year ago: Last time, we talked about a quick and easy way to get a memory dump on a Windows based PC. This tim … more →

Tags: Computer Security, Forensics, memory analysis, Memory Dumper, Microsoft Windows, Password Recovery

The Importance of Memory Search and Analysis

forensicfocus wrote 1 year ago: First published October 2009 by Access Data www.accessdata.com Introduction Historically, criminal o … more →

Tags: Methodology, Software, access data, FTK

Digital forensics of the physical memory

forensicfocus wrote 1 year ago: First published September 2005 Mariusz Burdach Mariusz.Burdach@seccure.net Warsaw, March 2005 last u … more →

Tags: Methodology, memory analysis

Using "volatility" to study the CVE-2011-0611 Adobe Flash 0-day

wikihead wrote 2 years ago: A very good explanation of memory forensic analysis using volatility of a memory dump after infectio … more →

Tags: Articles, notes, malware analysis, Zero Day

Real-World Cyber Forensics Training

cyberviewpoints wrote 2 years ago: I’d like to share with you a new type of training (hands-on how-to training) that you, your st … more →

Tags: cyber security and forensics investigations, malware analysis, incident response, Computer Forensics, malicious document analysis, hands-on how-to training


Related Tags
All →

Follow this tag via RSS