Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 57 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Forensics
Dumping memory and browsing through it
EH-Net
May 24, 2013, 07:40:42 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Forensics
(Moderator:
don
) >
Dumping memory and browsing through it
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Dumping memory and browsing through it (Read 6214 times)
0 Members and 1 Guest are viewing this topic.
kamikaze_fish
Newbie
Offline
Posts: 2
Dumping memory and browsing through it
«
on:
June 08, 2011, 12:06:14 PM »
I'm new to computer forensics but I'm trying to figure out how to dump the data in the physical memory, maybe to a flash drive, and what can I use to browse that dump? I was looking at win32dd and win64dd and possibly using volitility to browse the contents but not sure if there's something better to use or would someone can point me to training material
Logged
sil
Hero Member
Offline
Posts: 549
Re: Dumping memory and browsing through it
«
Reply #1 on:
June 08, 2011, 12:52:05 PM »
If you're a glutton for punishment, Mandiant Memorize + WinDBG will get you ALL you will need (
http://www.mandiant.com/products/free_software/memoryze/
)
Volatility works just fine without the hassles of getting your hands really dirty as well. WMFT is alright as well but any of the ones mentioned should get you started and finished.
http://www.mandiant.com/products/free_software/memoryze/
http://forensic.seccure.net/tools/wmft_0.2.zip
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
sil
Hero Member
Offline
Posts: 549
Re: Dumping memory and browsing through it
«
Reply #2 on:
June 08, 2011, 04:23:45 PM »
You could also use DFF see 2 minute video walkthrough
http://www.infiltrated.net/dff-walkthrough/
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
R3B005t
Newbie
Offline
Posts: 43
Re: Dumping memory and browsing through it
«
Reply #3 on:
June 10, 2011, 01:36:07 PM »
Sil what are you thoughts on DFF? I'm playing around with it and find it to be pretty robust so far, I'd recommend kamikaze go for the Mandiant Memorize and the Memorize viewer initally till he gets more comfortable with the more advanced memory forensic tools. There really is no end to memory analysis kit out there, if your comfortable with nix then you could play around with the sans sift workstation....
Actually Mandiant put out a new memory analysis tool called Redline, I have yet to play with it (dling now) but it might be worth looking into, overall I think the make a decent product. So to recap Memoryze & Audit Viewer, or Redline would be great starting points.
«
Last Edit: June 10, 2011, 01:41:24 PM by R3B005t
»
Logged
sil
Hero Member
Offline
Posts: 549
Re: Dumping memory and browsing through it
«
Reply #4 on:
June 10, 2011, 01:56:11 PM »
DFF is alright, nothing more than a GUI for most other tools. I like to use old school *nix tools via cli most of the times. I can do so from anywhere and the results are the same. It also helps keeping me on my toes via way remembering things.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
kamikaze_fish
Newbie
Offline
Posts: 2
Re: Dumping memory and browsing through it
«
Reply #5 on:
June 10, 2011, 02:48:35 PM »
Thank you Sil. Great information and you've definitely given me a god start.
Logged
nebu10uz
Sr. Member
Offline
Posts: 368
Re: Dumping memory and browsing through it
«
Reply #6 on:
June 10, 2011, 03:20:53 PM »
Yeah, I like Memorize and you can make it portable too. I added it to my Iron Key USB flash drive as part of my tool kit. You just have to make sure to run it once from your flash drive with write-mode enable to let it copy some additional files.
Also, last week I had the chance to play around with Redline. I like it except that you need .Net Framework version 4 or greater to use it on your Windows machine. Currently, it's very slow in analyzing memory dumps and it doesn't work well with Windows 7. But hey, it's new and I'm sure that Mandiant will improve it and make it better. I do recommend for beginners to take look at Redline and use it because it walks you through with explaination on quickly detecting suspicious or potentially malicious processes and etc.
Btw, Don, I can't thank you enough for the Iron Key flash drive. I can't live without it! Since I can unlock the Iron Key in read-mode only, it's perfect for incident response and malware forensic. You don't have to worry about your flash drive getting infected. I know it has been more than a year that I received my Iron Key, but I just wanted to say thanks again.
Logged
Security+, OSCP, CEH
R3B005t
Newbie
Offline
Posts: 43
Re: Dumping memory and browsing through it
«
Reply #7 on:
June 12, 2011, 02:10:28 PM »
Yeah redline has potential I hate the .net requirement and keep in mind this is the first release of the product.. Things I have on my Ironkey-Sysinternals suite, mir standalone scan (we do have an appliance but you never know when you need to do the odd offline capture) I tossed redline on there as well as a few other custom goodies. Only beef I have with the iron key is that its a thousand times bigger than any other memory key I have. Over all though the product roxxs.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.