Notifications
Clear all

RAM Memory Dump.

12 Posts
10 Users
0 Reactions
1,060 Views
pajkow
(@pajkow)
Estimable Member
Joined: 17 years ago
Posts: 81
Topic starter  

Hi Folks

I’m looking for something efficient to catch volatile RAM memory from the PC (XP, Vista) In order not to destry the evidence I would like to use something networked and not to use this machine at all, knowing the IP address would like to be able to catch all RAM memory of this machine for further analysis, does that tool exists?

Something with graphic interface would’ve been very helpful D

If not, could you give me efficient software to catch if from the LIVE CD to put into the CD room of the suspect’s machine and save results somewhere on the network for further analysis.

Many Thanks.

Pajkow 


   
Quote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

This is one avenue that I have started using with success F-Response - The Long Road to Physical Memory.

There are also a number of Enterprise tools available that work well in a corporate environment.


   
ReplyQuote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

Good afternoon,

Mantech's mdd appears to be one of the better memory collection tools available

http//www.mantech.com/msma/mdd.asp

Volatility will help you analyze it

https://www.volatilesystems.com/default/volatility#overview

Apparently the latest version of EnCase, or a recent EnScript, will also do memory analysis.

-David


   
ReplyQuote
(@fresponse_s)
Trusted Member
Joined: 17 years ago
Posts: 70
 

This is one avenue that I have started using with success F-Response - The Long Road to Physical Memory.

There are also a number of Enterprise tools available that work well in a corporate environment.

Thanks BH, we've gotten a good bit of positive feedback so far on F-Response 2.03.

Warmest Regards,

M. Shannon, Founder, F-Response


   
ReplyQuote
neddy
(@neddy)
Estimable Member
Joined: 21 years ago
Posts: 182
 

If not, could you give me efficient software to catch if from the LIVE CD to put into the CD room of the suspect’s machine and save results somewhere on the network for further analysis.

Hi

The newest versions of EnCase & Helix contain Winen, this may satisfy the last resort. More info here;
http//forensiczone.blogspot.com/2008/06/winenexe-ram-imaging-tool-included-in.html
The author of this article also mentions another tool that he uses; http//gmgsystemsinc.com/knttools/


   
ReplyQuote
(@bitsec)
New Member
Joined: 17 years ago
Posts: 2
 

All great suggestions.

For the remote acquisition, F-Response is a great solution. Combining that with your imaging tool of choice is a very good way to capture RAM over the network. It sees RAM as a physical device, like a hard drive. Very cool….

For local acquisition, when possible I like running my tools from a USB hard drive (thumbs are way to slow to be practical). I am fond of MDD and WinEn. Other solutions exist; however, these two offer some of the widest compatibilities (i.e. Vista and 2003).

For analysis, I like Volatility, HB Gary Responder, and good old EnCase or FTK. Mantech has just released Memoryze as well.

Our company, BitSec Forensics, offers a two day course on the Acquisition and Analysis of physical memory. We offered an abbreviated version of the course HTCIA in Atlantic City. Please feel free to download a copy of those materials at http//www.bitsecforensics.com/htcia08.pdf . We're hosting a full two day course in March. Details are available at http//www.bitsecforensics.com/Courses/livedc09.html

Mike Webber
BitSec Forensics


   
ReplyQuote
(@fresponse_s)
Trusted Member
Joined: 17 years ago
Posts: 70
 

Bump!

F-Response 2.04 Beta is now available.

www.f-response.com

Thanks!

M. Shannon, F-Response


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Mantech has just released Memoryze as well.

Mantech, or Mandiant?


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

AIYDK. Mandiant.


   
ReplyQuote
(@echo6)
Trusted Member
Joined: 21 years ago
Posts: 87
 

EnCase has acknowledged that there is a bug in winen which blanks out the first page of memory..Feature / bug #24597


   
ReplyQuote
Page 1 / 2
Share: