Speaker: Peter Cowman
Abstract: Memory forensics has become a cornerstone of security investigations - whether it be Police running forensics on a confiscated machine or an organisation launching a response to a security incident, an image of a suspect device’s hard drive is normally taken as a matter of course.
There is now malware out in the wild which is present only in volatile memory for much of it's lifespan. This presents a whole new set of problems to the forensic process, not least of which are the security systems in place within an OS to control memory access.
This talk covers a project investigating the potential for live monitoring of RAM while a system is running normally. An overview of the challenges of volatile memory analysis will be given, along with the ways these can be overcome. We'll also have a look at any interesting data I've come across during the project which it shouldn't be possible to see normally.