Quick question, what software/techniques do people use for the live acquire of live resident ram data? I've never actually needed to do this in 3 years..first time for everything. I have physical access to the system..and It cannot be rebooted.
Regards
Helix, F-responce, HBGary, FTK Imager light or Linux with Python and iPod driver. It cannot be rebooted? If you reboot, what is the point getting the RAM? I am sure the list of tools can be bigger. What OS?
Regards.
I like mdd.exe, it's command line, very small, and more idiot proof than using a variant of dd.
I like mdd.exe, it's command line, very small, and more idiot proof than using a variant of dd.
…and no longer supported.
I presume these can all be used without altering the system, live run via CD/USB?
Be sure to check out windd, as well
http//
George M. Garner Jr's variation on dd.exe is no longer available through his site, and only worked on Windows 2000 and XP; as of Windows 2003 SP 1, it was not an option.
I presume these can all be used without altering the system, live run via CD/USB?
No. Any action taken on a live system, even inaction, will alter a system in some respect.
Insert the USB device, system is altered. Run a program, the system is altered. The system is altered as you stand there and watch it, doing nothing.
The question isn't whether the system is altered or not…the question is whether that alteration can be shown to materially affect your findings or not. If you can justify the acquisition, and thoroughly document it…much easier when it's part of a standard process…then what's the issue? Crime scenes in the real world are subject to similar phenomena…
The question isn't whether the system is altered or not…the question is whether that alteration can be shown to materially affect your findings or not.
The above quote needs to be put on a poster or something, and placed in every forensics lab. I go blue in the face trying to explain this sometimes…far less effectively, mind you. Ah, the gift of language.
This "keydet89" person should write a book or something.
Barry
So should that "bgrundy" person…
The system is altered as you stand there and watch it, doing nothing.
Yep D , that's how traditionally evil eye is depicted
http//
mrgreen
OT, but not much, anyone have experimented with RAM freezing?
http//
jaclaz