• GitHub
  • Contact
The Volatility Foundation - Promoting Accessible Memory Analysis Tools Within the Memory Forensics Community
  • The Volatility Framework
  • Training
  • Events
  • FAQ
  • Contest
  • About
  • Blog
Select Page

MoVP 3.5: Analyzing the 2008 DFRWS Challenge with Volatility

by Volatility | Sep 28, 2012 | forensics, kernel, linux, movp, volatility

In this blog post I will go through analyzing the memory sample that was part of the 2008 DFRWS challenge.  This challenge was focused on a Linux computer that had sensitive files transferred from it. Due to its complexity and thoroughness, the challenge is well...

MoVP 3.4: Recovering tagCLIPDATA: What’s In Your Clipboard?

by Volatility | Sep 27, 2012 | forensics, kernel, malware, movp, volatility, windows

Month of Volatility Plugins Determining what’s in a computer’s clipboard can be a valuable resource. If you remember from MoVP 1.1 Logon Sessions, Processes, and Images, we traced an RDP user’s actions by dumping his command history and making note of the FTP...

MoVP 3.3 Analyzing USER Handles and the Win32k.sys Gahti

by Volatility | Sep 26, 2012 | forensics, kernel, malware, movp, volatility, windows

Month of Volatility Plugins Since the early days of memory forensics, tools have analyzed kernel/executive objects such as processes, threads, mutexes, open files, and registry keys. In fact, I would consider that a basic capability of any framework. One thing that...

MoVP 3.2 Shellbags in Memory, SetRegTime, and TrueCrypt Volumes

by Jamie Levy | Sep 25, 2012 | forensics, movp, registry, volatility, windows

HowTo: Scan for Internet Cache/History and URLs

by Volatility | Sep 24, 2012 | forensics, malware, volatility, windows

This post will describe how you can leverage the flexibility of the Volatility framework to locate IE history from Windows memory dumps. Such artifacts have traditionally not been a priority, because the data is in user-mode (i.e. index.dat mappings) and...
« Older Entries

Volatility Blog Archive

2025

  • + July (1)
  • + May (2)
  • + March (1)

2024

  • + August (1)
  • + July (1)
  • + March (1)

2023

  • + August (1)
  • + July (1)
  • + June (1)
  • + March (1)
  • + February (1)
  • + January (1)

2022

  • + July (1)
  • + February (1)
  • + January (1)

2021

  • + October (1)
  • + August (1)
  • + May (1)
  • + January (1)

2020

  • + November (1)
  • + May (2)

2019

  • + November (1)
  • + October (2)
  • + July (1)
  • + June (1)

2018

  • + November (2)
  • + May (1)
  • + February (1)

2017

  • + November (1)
  • + June (1)
  • + April (1)

2016

  • + December (2)
  • + September (1)
  • + August (2)
  • + July (1)
  • + April (3)

2015

  • + November (2)
  • + October (1)
  • + August (2)
  • + July (2)
  • + June (1)
  • + May (1)
  • + March (1)
  • + February (1)
  • + January (1)

2014

  • + December (1)
  • + October (3)
  • + September (5)
  • + August (6)
  • + July (2)
  • + May (1)
  • + April (2)
  • + February (2)
  • + January (5)

2013

  • + October (3)
  • + September (2)
  • + August (1)
  • + June (9)
  • + May (15)
  • + April (2)
  • + March (2)
  • + February (1)
  • + January (4)

2012

  • + December (2)
  • + November (1)
  • + October (14)
  • + September (19)
bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

     

    Loading Comments...
     

    You must be logged in to post a comment.