Digital forensic examiners are investigators who are experts in gathering, recovering, analyzing, and presenting data evidence from computers and other digital media related to computer-based .They might work on cases concerning identity theft, electronic fraud,investigation of material found in digital devices ,electronic evidence, often in relation to cyber crimes.
Showing posts with label Memory Forensics. Show all posts
Showing posts with label Memory Forensics. Show all posts
Launch FTK Imager: Open the FTK Imager application on your computer.
Initiate memory capture: Click on File in the top menu bar, then select Capture Memory.
Configure destination:
Click the browse button (...) next to Destination Path.
Navigate to and select a folder where you want to save the image, preferably an external drive.
Enter a filename for the memory dump (e.g., memdump.mem).
Set options (optional but recommended):
Include pagefile: Check the box to include the pagefile in the capture, which can provide additional data.
Create AD1 file: Check this box to create a single, compressed, and hashed image file that includes the memory dump and pagefile (if selected).
Start the capture: Click the Capture Memory button to begin the process. A progress bar will show the status, and you will need to wait for it to finish.
Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders
Cyberdefenders: DumpMe
Description
One of the SOC analysts took a memory dump from a machine infected with a meterpreter malware. As a Digital Forensicators, your job is to analyze the dump, extract the available indicators of compromise (IOCs) and answer the provided questions.
Q1 What is the SHA1 hash of Triage-Memory.mem (memory dump)?
Belkasoft Live RAM Capturer เข้ากันได้กับ Windows รุ่น 32 บิตและ 64 บิต รวมถึง XP, Vista, Windows 7/8/10/11, 2003 และ 2008 Server ไม่จำเป็นต้องติดตั้งเครื่องมือนี้และสามารถเปิดใช้งานได้ภายในไม่กี่วินาทีจากไดรฟ์ USB
การสำเนาหน่วยความจำ(Memory dumps )
Belkasoft Live RAM Capturer มีขนาดเล็กที่สุด ไม่จำเป็นต้องติดตั้ง และสามารถเปิดใช้งานได้ภายในไม่กี่วินาทีจากแฟลชไดรฟ์ USB ซึ่งแตกต่างจากเครื่องมือคู่แข่งอื่นๆ ที่ทำงานในโหมดผู้ใช้ของระบบ Belkasoft Live RAM Capturer มาพร้อมกับไดรเวอร์เคอร์เนล 32 บิตและ 64 บิต ซึ่งช่วยให้เครื่องมือทำงานในโหมดเคอร์เนลที่มีสิทธิพิเศษสูงสุด หน่วยความจำที่ถ่ายโอนได้จาก Belkasoft Live RAM Capturer สามารถวิเคราะห์ได้ด้วย Belkasoft X
Loading device driver ...
Physical Memory Page Size = 4096
Total Physical Memory Size = 9718 MB
Memory dump completed. Total memory dumped = 9718 MB
ท่านสามารถใช้ WannaKiwi และยืนยันว่าสามารถปลดล็อก WannaCry บน Windows XP และ Windows 7 ได้เงื่อนไขเบื้องต้นในการปลดรหัสได้สำเร็จต้องมีอย่างน้อย 2 รายการเช่นเดียวกับ WannaKey คือ