Leveraging CybOX with Volatility
by Jamie Levy | Sep 5, 2013 | cybox, forensics, malware, volatility
Lately I’ve been playing around with Cyber Observable eXpression, CybOX, and created a plugin to help check for threat indicators in memory samples. In case you don’t know, CybOX provides a vendor neutral format for expressing indicator information. As of...Memory Forensics Training – Reston, VA – November 2013
by Volatility | Jun 25, 2013 | forensics, malware, training, volatility, windows
The next journey to the center of Windows Memory Forensics starts in Reston, VA this November! This event will be the 5th public offering of the Windows Malware and Memory Forensics Training by The Volatility Project. This is the only memory forensics course...The Perfect Combination of IR, Malware, Forensics, and Winternals
by Volatility | Jun 20, 2013 | forensics, malware, training, volatility, windows
Our Windows Malware and Memory Forensics training course has been described as the “…perfect combination of incident response, malware analysis, memory forensics, and Windows internals.” As you can see below, we do in fact disseminate quite a bit of...MOVP II – 4.5 – Mac Volatility vs the Rubilyn Kernel Rootkit
by Volatility | Jun 11, 2013 | forensics, kernel, macosx, malware, movp, volatility
In our final Month of Volatility Plugins post, we are going to demonstrate a number of plugins that can be used to detect kernel level OS X rootkits. To show these capabilities I am going to analyze a system that is infected with the rubilyn rootkit. I want to thank...MOVP II – 4.4 – What’s in Your Mac OSX Kernel Memory?
by Volatility | Jun 9, 2013 | forensics, kernel, macosx, movp, volatility
Today’s post will discuss a number of plugins that can retrieve forensically interesting information from within the kernel. Keep in mind, you can also use mac_yarascan to search kernel memory with yara signatures and you can use mac_volshell as an interactive...
You must be logged in to post a comment.