Full Disclosure mailing list archives

Re: Break-in discovery and forensics tools


From: "yannick san" <yannicksan () free fr>
Date: Wed, 23 Apr 2003 11:55:50 +0200

Hello,

I've seen on the netsys mailing list that you were doing a CD with tools
used for a forensic analysis.
Well, I have 2 questions.
Will it be possible to buy a copy of it when it will be done ?
I'm looking for tools for saving the state of the RAM memory into a file.
Did you find some ? When a machine is compromised, an hacker could have
loaded some information or progs into the memory, and if we shut down the
machine without saving the state of the RAM, I think we could loose some
very precious information. Saving the state of the RAM before rebooting
could be very usefull in forensic analysis.

Receive my best regards

Yannick
Information Security Engineer
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: