Android Application (Dalvik) Memory Analysis & the Chuli Malware
by Volatility | Apr 1, 2013 | android, forensics, malware, volatility
This blog serves to highlight a recent collaborative effort between myself and Joe Sylve and Vico Maziale of 504ensics Labs. In this effort, we added to Volatility the capability to perform deep, per-application analysis of running Android applications. Each...Official Training by Volatility – Reston/VA, June 2013
by Volatility | Mar 18, 2013 | forensics, malware, training, volatility, windows
The next journey to the center of Windows Memory Forensics starts in Reston, VA this June! We are pleased to announce the 3rd public offering of the Windows Malware and Memory Forensics Training by The Volatility Project. This is the only memory forensics course...If You’re Going to Cheat…
by Volatility | Mar 15, 2013 | forensics, training, volatility, windows
If you’re going to cheat, might as well use an official cheat sheet! Need some help navigating through all of Volatility’s plugins and options? Want a birds-eye view of the framework’s major capabilities for Windows operating systems? Not sure where...Memory Forensics Talk at RSA!
by Volatility | Feb 15, 2013 | forensics, malware, volatility, windows
On Wednesday of RSA ( X rsaconference.com/events/2013/usa/index.htm) I will be giving a talk titled: “Memory Forensics: Defeating Disk Encryption, Skilled Attackers and Malware” This talk will focus on three key points: 1) Showcasing the power and...HowTo: Extract “Hidden” API-Hooking BHO DLLs
by Volatility | Jan 23, 2013 | code injection, malware, unpacking, volatility, windows
A Twitter user recently asked a question to the @volatility account: “can you please tell me how to extract SilentBanker [from memory]”? We like to encourage people to work through problems on their own, so our initial advice was short and sweet:...
You must be logged in to post a comment.