memory acquisition ...
 
Notifications
Clear all

memory acquisition on a running windows system

12 Posts
9 Users
0 Likes
819 Views
(@dnraikes)
Posts: 29
Eminent Member
Topic starter
 

I am trying to determine if a computer on my network has any malware on it, and one of the things that I keep seeing from my google searching is that I need a memory dump to analize.

How can I obtain a dump of the system's memory without introducing any new artifacts into it (or at least minimizing the impact)?

What tools are good for this kind of work?

 
Posted : 01/10/2011 12:43 am
(@xennith)
Posts: 177
Estimable Member
 

MDD

 
Posted : 01/10/2011 2:25 am
(@dnraikes)
Posts: 29
Eminent Member
Topic starter
 

I also see a tool called win32dd which looks promising, however, I can't find a copy of it anywhere.

 
Posted : 01/10/2011 4:51 am
(@dnraikes)
Posts: 29
Eminent Member
Topic starter
 

It looks like mdd only comes in source format and requires visual studio to compile it. Need to work that detail out -)

 
Posted : 01/10/2011 4:52 am
(@xennith)
Posts: 177
Estimable Member
 

Try FTK imager (lite) then. Its free and everything but does have a bigger memory footprint than MDD.

Oh, and I've compiled MDD.exe for you - http//dl.dropbox.com/u/21460656/mdd.exe you can trust me 😉

 
Posted : 01/10/2011 5:01 am
(@twjolson)
Posts: 417
Honorable Member
 

To answer your question, everything you do will introduce artifacts. To image memory, a program has to be run, to run, the program has to be in memory, that program in memory has possibly overwritten, or shuffled data to pagefile.sys, other programs/data.

 
Posted : 01/10/2011 5:58 am
LittleMac
(@littlemac)
Posts: 17
Active Member
 

dumpit by moonsols, is self-contained executable for 32-bit or 64-bit systems, collection only.

also memoryze and redline by mandiant; memoryze is the collection & analysis engine bit (CLI), redline is the GUI front-end that automates analysis. 32 or 64-bit systems.

hbgary has community edition which is free, but only handles 32-bit, collection and analysis.

ftk imager lite will collect on 32 or 64-bit, but is only on 2.9, which apparently (according to v3 release notes) has some issues with 64-bit ram.

hope that helps

 
Posted : 01/10/2011 7:58 am
jhup
 jhup
(@jhup)
Posts: 1442
Noble Member
 

Firewire.

 
Posted : 01/10/2011 9:53 am
(@c-r-s)
Posts: 170
Estimable Member
 

When you sign up at HBGary you can obtain (besides Responder CE) a free version of their acquisition tool, I think.

 
Posted : 02/10/2011 6:04 pm
(@athulin)
Posts: 1156
Noble Member
 

I am trying to determine if a computer on my network has any malware on it, and one of the things that I keep seeing from my google searching is that I need a memory dump to analize.

Apart from the usual forensic memory acqusition tools, it's also a good idea to be aware of tools such as Hijackthis from Trend, GMER, and RootkitRevealer from SysInternals – at least if the computer runs Windows.

 
Posted : 02/10/2011 10:38 pm
Page 1 / 2
Share: