2012-02-03から1日間の記事一覧

[memory] volafox

sec

Memory analyzer for Mac OS X & BSD http://code.google.com/p/volafox/SnowLeopardのメモリダンプ http://forensic.korea.ac.kr/volafox/files/SnowLeopard/MemoryImage.zip $ python volafox.py -i MemoryImage.mem -o proc_info [+] Memory Image: Memor…

[memory] Memoryze と Audit Viewer

sec

Memoryze http://www.mandiant.com/products/free_software/memoryze/Audit Viewer http://www.mandiant.com/products/free_software/mandiant_audit_viewer/ >Process.bat -input memory_dump.raw -handles true -sections true -ports true -injected true…

[memory] Volatility

sec

A)メモリのダンプMoonSols DumpIt MoonSols DumpIt goes mainstream ! | MoonSols B)メモリの解析 Volatility-2.0 https://www.volatilesystems.com/default/volatility Usage: Volatility - A memory forensics analysis platform.Options: -h, --help list…