7. Memory Analysis Flashcards

1
Q

Why Analyze Memory?

A
  1. Malware has to execute.
  2. Everything that execute, runs through RAM
  3. Therefore, Malware has to run through RAM
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How to preserve RAM.

A

Infected Machine should be left running.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What it Fileless malware

A

Does not touch the disk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Encrypted Systems

A
  1. CPU runs in clear text.

2. Decryption first before running.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Dump Format: RAW

A

Live memory acquisition tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Dump Format: Crash Dump

A

Generated during a crash

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Dump Format: hiberfil.sys

A

Windows (laptops). Created during hibernation mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Dump Format: EWF

A

Expert Witness Disk Image Format (EnCase)

Standard for analyzing memory Dumps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Dump Format: AFF4

A

WinPMEM.Memory Dump

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Analysis Frameworks

A
  1. Rekall

2. Volatility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Volatility

A

Best known. Windows, Linux, Mac.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Rekall

A

Develop by Google

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Six Investigation Steps

A
  1. Processes
  2. DLL and Handles
  3. Network
  4. Code Injection
  5. RootKits
  6. Dump
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is KDbg?

A

KDbg is a data structure for RAW memory image.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Memory Profile

A

Different Windows version have different profiles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

VM Metadata

A

Memory Images from VM contain Metadata

17
Q

Why image conversion?

A

Volatility: needs RAW memory image.