Username / email:   Password:
or or
Exit Theater Mode

Login or register to enable this feature.

Or, compose an email to send yourself.

Share this video
  • Share via email

View by:

Rob Fuller, aka Mubix, of Room362.com joins us to expand on last week's discussion about the Cold Boot attacks. We cover retrieving memory from live systems, analysis with tools like volatility, and file recovery with foremost. Mubix calls it forensics for the gray hat.

After You've Captured the RAM

Once we've captured our memory it's time to run it through a few tools to extract the good bits. Last week we touched on AESKeyFinder and RSAKeyFinder as well as Strings. This week we're using the epic memory artifact extraction utility Volatility.

Tell your friends about this video:

What's in your RAM?

Tuesday, July 14th, 2009

All Segments From This Episode