SOCC05 - Memory Forensics
Memory Forensics
- Situation of Memory Analysis
- Virtualized Servers
- Snapshots capture the memory of the server, and can give you access to the memory
- Windows makes it hard, but not impossible...
- Virtualized Servers
- Volatility
- Great tool for analyzing memory
- Network, processes, DLL, etc.
- Volatility GUI
- Volatility 3 CheatSheet - onfvpBlog