Advanced Memory Forensics
Advanced Memory Forensics
The data in live system memory is invaluable for both offense and defense.
6
Value of Live System Memory
Red Team vs Blue Team
“Offense” “Defense”
System Memory
“shared battlefield”
Deprecate
7
/Bypass EDR
If you are not analyzing memory,
what are you missing?
Unpacked Memory-
Registry Clipboard Data
versions of mapped files
keys/values
programs
sans.org/for526
8
History of FOR526 NEW
you
Things
ow
Since the course launch in Aug 2012: don’t kn
sans.org/for526
Feedback from FOR526 Students
Q1 2017-Q2 2018
• “I think this class needs bootcamp.” SANS2018 Orlando
• “Due to the lack of time the teacher has to go fast. I would prefer to stay 1 hour
more and go deep in several content sometimes is complex and needs more
time to be understood.” London May 18
• “Definitely more Netwars in the afternoon. If possible, I would like to have
Netwars every day in the afternoon.” Prague 2017
• “Daily Challenges really help cement knowledge going through the course.”
London May 18
• “Netwars was really great.” Day 4 - London May 18
• “Add a new rating choice - Amazing!” Day 6 - London May 18
• “Sometimes too much guided [exercises]” - London May 18
6-Day Bootcamp Course Agenda
C:\Users\<profile>\AppData\Local\ConnectedDevicesPlatform\L.<profile>\ActivitiesCache.db
https://binaryforay.blogspot.com/2018/05/introducing-wxtcmd.html
Hibernation Recon
Lab Components
1. Open crash dump with WinDbg.
2. Enumerate processes and loaded modules from dump.
3. Using Swishdbg WinDbg extension, obtain list of loaded hives.
NetWars Day 6 Challenge:
“May the odds be ever in your favor”
Tournament Level Progression
All Levels, All Modules
Total 2,460 Points