MoVP 2.5: Investigating In-Memory Network Data with Volatility
by Volatility | Sep 21, 2012 | forensics, kernel, linux, volatility
Month of Volatility Plugins In this post I will discuss Volatility’s new Linux features related to recovering network information. This will include enumerating sockets, network connections, and packet contents. The post will discuss each plugin along with...MoVP 2.4 Analyzing the Jynx rootkit and LD_PRELOAD
by Volatility | Sep 20, 2012 | forensics, linux, malware, volatility
Month of Volatility Plugins In this post I will analyze the Jynx rootkit using Volatility’s new Linux features. If you would like to follow along or recreate the steps taken, please see the LinuxForensicsWiki for instructions on how to do so....MoVP 2.3 Event Logs and Service SIDs
by Jamie Levy | Sep 19, 2012 | forensics, movp, volatility, windows
Month of Volatility Plugins In this post we will discuss how you can recover event logs from Windows XP/2003 machines from memory as well as how to calculate Service SIDs which can potentially be used to link specific event records with the windows service that...MoVP 2.2 Malware In Your Windows
by Volatility | Sep 18, 2012 | forensics, kernel, malware, movp, volatility, windows
Month of Volatility Plugins So far in the Windows GUI memory space, an area previously unexplored by forensic and malware analysis tools, you have seen sessions, window stations, desktops and atoms. Today’s MoVP 2.2 post is about windows. Windows...
You must be logged in to post a comment.