Practical Memory Forensics by Svetlana Ostrovskaya & Oleg Skulkin
Author:Svetlana Ostrovskaya & Oleg Skulkin
Language: eng
Format: epub
Publisher: Packt
Published: 2022-12-15T00:00:00+00:00
As you have already noticed, there are various types of timelines. We will talk about those that can be built using memory dumps.
Filesystem-based timelines
This timeline is based on filesystem metafiles. For NTFS, this file would be, for example, the Master File Table ($MFT). This file contains information about all files of the filesystem and their timestamps.
To build a timeline based on $MFT, first, we need to get its data. This can be done with the Volatility mftparser plugin, which collects all $MFT entries from memory. Running this plugin will look like this:
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Cryptography | Encryption |
Hacking | Network Security |
Privacy & Online Safety | Security Certifications |
Viruses |
Effective Threat Investigation for SOC Analysts by Yahia Mostafa;(6185)
Practical Memory Forensics by Svetlana Ostrovskaya & Oleg Skulkin(5880)
Machine Learning Security Principles by John Paul Mueller(5866)
Attacking and Exploiting Modern Web Applications by Simone Onofri & Donato Onofri(5526)
Operationalizing Threat Intelligence by Kyle Wilhoit & Joseph Opacki(5509)
Solidity Programming Essentials by Ritesh Modi(3825)
Microsoft 365 Security, Compliance, and Identity Administration by Peter Rising(3473)
Mastering Python for Networking and Security by José Manuel Ortega(3314)
Future Crimes by Marc Goodman(3303)
Mastering Azure Security by Mustafa Toroman and Tom Janetscheck(3303)
Blockchain Basics by Daniel Drescher(3266)
Operationalizing Threat Intelligence by Joseph Opacki Kyle Wilhoit(3184)
Learn Computer Forensics - Second Edition by William Oettinger(2978)
Mobile App Reverse Engineering by Abhinav Mishra(2859)
Mastering Bitcoin: Programming the Open Blockchain by Andreas M. Antonopoulos(2832)
The Code Book by Simon Singh(2767)
From CIA to APT: An Introduction to Cyber Security by Edward G. Amoroso & Matthew E. Amoroso(2756)
Incident Response with Threat Intelligence by Roberto MartÃnez(2672)
The Art Of Deception by Kevin Mitnick(2577)
