Topic 9. Mem-Forensics
Topic 9. Mem-Forensics
Mem-Forensics
( Memory Forensics with Volatility )
Memory protection.
Location of both the modes in RAM.
Page directory and Page Table?
User mode vs Kernel mode?
User/kernel Mode (Cont)
User/kernel Mode (Cont)
User/kernel Mode (Cont)
Virtual Memory to physical memory
Virtual Memory to physical memory (Cont)
What can be found in memory
Capture memory.
Analyze the memory.
Reconstruct of the memory state.
Various Formats
Go to labs.
Q&A