MoVP 1.5 KBeast Rootkit, Detecting Hidden Modules, and sysfs
by Volatility | Sep 14, 2012 | forensics, kernel, linux, malware, movp, volatility
Month of Volatility Plugins In this post I will analyze the KBeast rootkit using Volatility’s new Linux features. This will include finding hidden modules, network connections, opened files, and hooked system calls. If you would like to follow along or recreate...MoVP 1.4 Average Coder Rootkit, Bash History, and Elevated Processes
by Volatility | Sep 13, 2012 | forensics, kernel, linux, malware, movp, volatility
Month of Volatility Plugins In this post I will begin showcasing some of Volatility’s new Linux features by analyzing a popular Linux kernel rootkit named “Average Coder”. These new features will include recovering .bash_history from memory, finding userland...MoVP 1.3 Desktops, Heaps, and Ransomware
by Volatility | Sep 12, 2012 | forensics, kernel, malware, movp, volatility, windows
Month of Volatility Plugins The MoVP 1.3 plugin, named deskscan, enumerates desktops, desktop heap allocations, and associated threads. In the GUI landscape, a desktop is essentially a container for application windows and user interface objects. Malware...MoVP 1.2 Window Stations and Clipboard Malware
by Volatility | Sep 11, 2012 | forensics, kernel, malware, movp, volatility, windows
Month of Volatility Plugins We previously discussed sessions, which are containers for processes and other objects related to a user’s logon session. Among those other objects are window stations, which act as security boundaries for processes and...
You must be logged in to post a comment.