Skip to content

Latest commit

 

History

History
19 lines (10 loc) · 711 Bytes

comparing_host_images_memory_dumps_to_known_good_baselines.md

File metadata and controls

19 lines (10 loc) · 711 Bytes

Comparing Host Images/Memory Dumps to Known-Good Baselines

Purpose: Identify deviations from "known-good" which might tend to indicate the presence of malware on a system

Data Required: Memory dumps, Registry dumps, "known good" data

Collection Considerations: This works best when tracked over time rather than as a single comparison. Volatility plugins such as "stalker", "profiler", "regcomp" & "hunter" are useful

Analysis Techniques:

Description

Other Notes

More Info

  • Every Step You Take (video needed, if available)
  • “Several Ways to Skin a Rat", Jamie "Gleeda” Levy (Link needed)