What is Random Access Memory?

แชร์
ฝัง
  • เผยแพร่เมื่อ 30 ก.ย. 2024

ความคิดเห็น • 13

  • @DFIRScience
    @DFIRScience  2 ปีที่แล้ว +1

    We have a whole course on RAM acquisition and analysis! Get 5% off FULL COURSE with this link learn.dfir.science/courses/RAM-Forensics-Tutorial?coupon=TH-camRAM5

  • @ciaobello1261
    @ciaobello1261 2 ปีที่แล้ว +1

    sry for the noob question.. its possible to collect RAM evidences for a Virtual Machine if, the Machine is a suspended/pause Mode?

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว +1

      From "inside" the virtual machine, no. But if the virtual machine is suspended, then a copy of RAM has most likely been written to the host machine. You can also use the virtual machine manager to dump the memory of the virtual machine. If everything else failed, you can copy the RAM of the host machine that will contain the memory of the virtual machine, but that would be difficult to investigate.

    • @ciaobello1261
      @ciaobello1261 2 ปีที่แล้ว

      @@DFIRScience Thank you for your replay

    • @Nonoss75
      @Nonoss75 2 ปีที่แล้ว +2

      If the software is Workstation, but I assume it is also true for other software, you can find a *.vmem and *.vmss files in the virtual machine folder.
      These are the RAM of your suspended machine and you need both to work with volatility for example.

    • @ciaobello1261
      @ciaobello1261 2 ปีที่แล้ว

      @@Nonoss75 cool, thanks for the advice

  • @SALTINBANK
    @SALTINBANK 2 ปีที่แล้ว

    Great video and thanks to dumping ram we can also bypass AES-256 XTS on warm and cold boot attacks ...
    Extract the FVEK from FS or RAM and mount the volume with BDE lib to mount the FS & Volatility to extract the key ...

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว

      Yes, it can. The original plugin to dump FVEK can be found here: github.com/volatilityfoundation/community/tree/master/MarcinUlikowski
      There are a few others that have written something based on the original: github.com/breppo/Volatility-BitLocker
      If you get the key you can use dislocker or Arsenal Image Mounter. Good luck!

  • @jawadikram5989
    @jawadikram5989 2 ปีที่แล้ว

    hahahaha

  • @Jenu-vh8yg
    @Jenu-vh8yg 2 ปีที่แล้ว

    man I missed this kind of tutorials lol. Great work here, thanks!!!

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว

      Thanks a lot! I'm working on a few more.

    • @niklasrabener7555
      @niklasrabener7555 11 หลายเดือนก่อน

      😢😂😢😢😊😂😊1😂😂😢😢😢😂😮