Windows physical me...
 
Notifications
Clear all

Windows physical memory analysis

12 Posts
5 Users
0 Reactions
1,396 Views
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
Topic starter  

I was wondering if anyone is doing any work in this area…specifically, analyzing dumps of Windows physical memory (ie, RAM) made using dd.exe.

I'm familiar with some of the work that has gone on already, particularly via the DFRWS 2005 Memory Challenge, as well as what Andreas Schuster has released recently (I've blogged on this already). What I'm trying to find is anyone else who's looking at this…

Thanks,

Harlan
http//windowsir.blogspot.com


   
Quote
 Andy
(@andy)
Reputable Member
Joined: 21 years ago
Posts: 357
 

Are you aware that WinHEX RAM editor in the Tools menu allows the examining of the virtual memory of a process? It can dump to a file, but its not the entire physical memory in one go like dd would do.


   
ReplyQuote
(@jsawyer)
Eminent Member
Joined: 20 years ago
Posts: 35
 

Harlan,

You left out pmodump.pl from the TRUMAN project by Joe Stewart from LURHQ.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
Topic starter  

Sorry, jsawyer. I've been searching all over the Net for the past couple of weeks, and in particular the past couple of days, and never saw a single reference to this at all. I've searched using combinations of "Windows", "physical memory", "RAM", "analysis", and "dd.exe"…so, I can't say that I really forgot it, as I never knew about it. Thanks for the pointer, though.

Harlan


   
ReplyQuote
(@jsawyer)
Eminent Member
Joined: 20 years ago
Posts: 35
 

I posted a link to it on Feb 28 in response to your post on the "volatile memory on windows" thread.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
Topic starter  

Sorry, I missed that one…I caught your previous post, however.

Harlan


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
Topic starter  

Andy, thanks, but that's really not what I'm looking for…

Harlan


   
ReplyQuote
(@jimmyw)
Trusted Member
Joined: 20 years ago
Posts: 64
 

Are you aware that WinHEX RAM editor in the Tools menu allows the examining of the virtual memory of a process? It can dump to a file, but its not the entire physical memory in one go like dd would do.

WinHex and X-Ways Forensics can dump the entire, physical RAM. You can open RAM, double-click Physical Memory, block the entire contents, and save it to a file. X-Ways also produces X-Ways Capture, which is designed for live acquisition, including physical RAM. I have a copy, but have to play with it some before I can comment further, although it seems quite handy and configurable.


   
ReplyQuote
sachin
(@sachin)
Eminent Member
Joined: 20 years ago
Posts: 28
 

I have no idea about DD but one more interesting thing I would like to share (might be known to the forum) is that the iPod can be used for memory dump analysis.
detail can be seen at-
http// www.pacsec.jp/psj04/psj04-dornseif-e.ppt


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
Topic starter  

sachin,

Thanks…but I'm not really clear on how that fits into the thread…

Harlan


   
ReplyQuote
Page 1 / 2
Share: