Hunting Malware Using Memory Forensics

In the chapters covered so far, we looked at the concepts, tools, and techniques that are used to analyze malware using static, dynamic, and code analysis. In this chapter, you will understand another technique, called memory forensics (or Memory Analysis).

Memory forensics (or Memory Analysis) is an investigative technique which involves finding and extracting forensic artifacts from the computer's physical memory (RAM). A computer's memory stores valuable information about the runtime state of the system. Acquiring the memory and analyzing it will reveal necessary information for forensic investigation, such as which applications are running on the system, what objects (file, registry, and so on) these ...

Get Learning Malware Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.