Use Discount Code SANSFIREISC10 when registering to get a 10% discount!!
MoVP II
Last Updated: 2013-05-23 14:00:31 UTC
by Adrien de Beaupre (Version: 1)
Volatility is a Python framework for performing memory forensics. If you haven't tried it yet I highly recommend it. The Volatility Month of Volatility Plugins II is on! As announced here: http://volatility-labs.blogspot.ca/2013/05/whats-happening-in-world-of-volatility.html Volatility 2.3 is entering beta and the second MoVP (Month of Volatility Plugins) has started and is actually in their second installment. Some very exciting new stuff:
1.1 - Mach-O Address Space
1.2 - VirtualBox ELF64 Core Dumps
1.3 - VMware Snapshot and Saved State Analysis
1.4 - New HPAK Address Space
1.5 - ARM Address Space (Volatility and Andriod / Mobile)
2.1 - RSA Private Keys and Certificates
2.2 - Unloaded Windows Kernel Modules
Cheers,
Adrien de Beaupré
Intru-shun.ca Inc.
My SANS Teaching Schedule
If you have more information or corrections regarding our diary, please share.
Diary Archive
| Date | Author | Title |
|---|---|---|
| 2013-05-23 | Adrien de Beaupre | MoVP II (1 Comments) |
| 2013-05-22 | Adrien de Beaupre | Privilege escalation, why should I care? (13 Comments) |
| 2013-05-21 | Adrien de Beaupre | Moore, Oklahoma tornado charitable organization scams, malware, and phishing (0 Comments) |
| 2013-05-20 | Johannes Ullrich | Ubuntu Package available to submit firewall logs to DShield (3 Comments) |
| 2013-05-20 | Guy Bruneau | Safe - Tools, Tactics and Techniques (0 Comments) |
| 2013-05-19 | Kevin Shortt | Port 51616 - Got Packets? (1 Comments) |
| 2013-05-17 | Daniel Wesemann | e-netprotections.su ? (3 Comments) |
| 2013-05-17 | Johannes Ullrich | SSL: Another reason not to ignore IPv6 (3 Comments) |
| 2013-05-16 | Joel Esler | Cisco TelePresence Supervisor MSE 8050 Denial of Service Vulnerability (1 Comments) |
| 2013-05-16 | Daniel Wesemann | Extracting signatures from Apple .apps (0 Comments) |
| Search Diaries: | |

Complete Archive

