Skip to Content
Malware Forensics Field Guide for Windows Systems
book

Malware Forensics Field Guide for Windows Systems

by Cameron H. Malin, Eoghan Casey, James M. Aquilina
May 2012
Intermediate to advanced
560 pages
12h 55m
English
Syngress
Content preview from Malware Forensics Field Guide for Windows Systems

Chapter 2

Memory Forensics

Analyzing Physical and Process Memory Dumps for Malware Artifacts

Solutions in this chapter:

• Memory Forensics Overview

• Old School Memory Analysis

• How Windows Memory Forensic Tools Work

• Windows Memory Forensic Tools

• Dumping Windows Process Memory

• Dissecting Windows Process Memory

Introduction

The importance of memory forensics in malware investigations cannot be overstated. A complete capture of memory on a compromised computer generally bypasses the methods that malware uses to trick operating systems, providing digital investigators with a more comprehensive view of the malware. In some cases, malware leaves little trace elsewhere on the compromised system and the only clear indications of compromise ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Malware Forensics

Malware Forensics

Eoghan Casey, Cameron H. Malin, James M. Aquilina
Malware Forensics Field Guide for Linux Systems

Malware Forensics Field Guide for Linux Systems

Eoghan Casey, Cameron H. Malin, James M. Aquilina

Publisher Resources

ISBN: 9781597494724