Section 3.3: Acquiring Memory Flashcards

1
Q

Tools to collect live memory from systems.

A

WinPMEM, DumpIt, F-Response, Belkasoft Live Ram Capturer, and Magnetic Forensics Ram Capture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Dead memory system files and where to locate them. Are they complete?

A

All of them are inside the SystemDrive: hiberfil.sys & memory.dmp are complete, pagefile.sys & swapfile.sys are partial.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When considering getting hibernation files, what else should be retrieved?

A

The live version of it if possible. That way to memories can show different stories. Hibernation can track weeks worth that a live one cant do.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Before analyzing hibernation files, it needs to be decompressed. What tools help with decompression?

A

Imagecopy plugin by Volatility, hibr2bin.exe by Comae, and Hibernation Recon by Arsenal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name the tools that can string/analyze memory images.

A

Volatility, BulkExtractor, Magnet AXIOM, and Passware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does power management play a crucial role in obtaining hibernation files?

A

Depending on the default shutdown state, it can make smaller hibernation files. Windows 8 has fast startup by default so it causes smaller files. Windows 10 has hybrid sleep causing more files. Use powercfg.exe to see the status.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How to create a virtual memory image available froma virtual machine.

A

Suspend the virtual machine and get the file this way.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Virtual machines and their virtual memory file extensions.

A

VmWare (vmem, vmss, vmsn), Hyper-V (bin, vsv), Parallels (mem), VirtualBox (sav).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What virtual machine may not be recognized by memory analysis tools?

A

VirtualBox because it only uses memory it needs, not as a whole. Volatility might be the only one.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Whats the fallback plan when trying to obtain memory acquisition?

A

Run a memory acquisition tool as a virtual guest. A raw image can be obtain this way.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

2 methods to look for the virtual memory files:

A

Inside the virtual memory file path or searching extension names.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly