Howto find Meterpre...
 
Notifications
Clear all

Howto find Meterpreter and similar rootkits?

11 Posts
6 Users
0 Reactions
707 Views
(@echo6)
Trusted Member
Joined: 21 years ago
Posts: 87
 

Take a look at Michael Hale Ligh's technique using Volatility.

http//mnin.blogspot.com/2009/01/malfind-volatility-plug-in.html

Also! you might want to consider looking at his book.

p.s. I would recommend using Volatility under Linux rather than Windows, some plugings require dependencies which you can't easily obtain under Windows. Of course you could go with Cygwin, but you may as well use native Linux or a vmware machine such as the one provided by SANS.


   
ReplyQuote
Page 2 / 2
Share: