MoVP II – 3.2 – Linux/Android Memory Forensics with Python and Yara
by Volatility | May 30, 2013 | android, forensics, kernel, linux, movp, volatility
In this post we will describe the Linux volshell and yarascan plugins. In previous releases of Volatility, these plugins only supported Windows samples, but starting with 2.3 you can interactively explore your Linux memory dumps (from a Python shell) or scan process...MoVP II – 3.1 – Linux CheckTTY & KeyboardNotifier Plugins
by Volatility | May 29, 2013 | android, forensics, linux, malware, movp, volatility
In this post we will discuss two new plugins in Volatility 2.3 that were contributed by Joe Sylve @jtsylve of 504ensics. These plugins are used to detect the two kernel-level keylogging techniques presented in “Bridging the Semantic Gap to...MOVP II – 1.5 – ARM Address Space (Volatility and Android / Mobile)
by Volatility | May 20, 2013 | android, linux, movp
In order to support Android, Volatility now includes an ARM address space. This is the first new hardware architecture supported by Volatility since the inclusion of Intel support in the earliest of releases. The creation of the address space was based upon the ARM...MoVP for Volatility 2.2 and OMFW 2012 Wrap-Up
by Volatility | Oct 12, 2012 | forensics, linux, movp, omfw, volatility, windows
The Month of Volatility Plugins and Open Memory Forensics Workshop 2012 have now come to an end. Volatility 2.2 has been released. We hope you enjoyed spending time with us learning about the new features and innovative research that’s being built into the...OMFW 2012: Datalore: Android Memory Analysis
by Volatility | Oct 12, 2012 | android, forensics, kernel, linux, omfw, volatility
This presentation went over the Android specific analysis capabilities of Volatility as well as showed how to use LiME to capture physical memory from Android devices. This functionality will be included in the 2.3 Volatility release. Author/Presenter: Joe Sylve /...
You must be logged in to post a comment.