Memory Forensics Baselines

Поділитися
Вставка
  • Опубліковано 2 лют 2025

КОМЕНТАРІ • 18

  • @sarunask.4406
    @sarunask.4406 4 роки тому +1

    I'm also a student in Digital Forensics and Cyber security.
    Your videos helped me with deciding what Final Year Project to choose.
    Very well laid-out explanations of complex things. Your videos are amazing - all of them. Time well spent. Thank you

  • @StaticReplication
    @StaticReplication 5 років тому +2

    Thank you so much for your videos. I've been going through them like crazy. I'm a student in Digital forensics but I want to move more towards IR and your videos are excellent for that.

  • @hejieronymus
    @hejieronymus 4 роки тому +1

    I'm having trouble with my volatility :( It doesn't seem to accept the baseline plugin :(

    • @13Cubed
      @13Cubed  4 роки тому

      What kind of error do you receive when you try?

    • @hejieronymus
      @hejieronymus 4 роки тому

      @@13Cubed I think it was the code itself? It doesn't seem to accept the inputs properly

  • @annafan83
    @annafan83 5 років тому +1

    Really cool! Thanks!

  • @emran5897
    @emran5897 5 років тому +1

    Thanks for the video...

  • @glowingone1774
    @glowingone1774 5 років тому +1

    thank you for your videos

  • @muhammadnoman06
    @muhammadnoman06 4 роки тому

    Hi Richard, I've watched both series windows and memory forensics, and I have practiced memory forensics enough by analyzing different malwares, now I'm forensicating my own laptop, one thing is irritating me that why driverbl plugin doesn't return anything, always the output is null. I've installed Magnet Ram capture today just to try it, through modules plugin i found that it loads the driver from the following directory C:\Users\Muhammad Noman\Downloads\MRCFA2D.tmp, and it is not found in the clean image that i had taken awhile back. Driverbl didnt notify me about that kernel loaded module. why?

    • @13Cubed
      @13Cubed  4 роки тому +1

      That series of plug-ins has not been updated in quite a while and I have seen issues with newer builds of Windows 10. Step back to an older version of Windows, like 7, and see if you have different results.

    • @muhammadnoman06
      @muhammadnoman06 4 роки тому

      @@13Cubed But I'm getting results for servicebl and processbl. Thanks for the reply Sir.

    • @13Cubed
      @13Cubed  4 роки тому +1

      Muhammad Noman Yes, it's driverbl that doesn't return results.

  • @FaRaH_xi
    @FaRaH_xi 5 років тому

    I really wanna try this but i don’t have a sift workstation and I have tried to download it from sans with my account it wasn’t work got some error. Any help? cuz I really wanna download that img. Anyhow, currently I have windows SIFT acquired it dyring my for500 course

    • @13Cubed
      @13Cubed  5 років тому

      You can install SIFT on top of an existing Ubuntu installation. Check this out: github.com/teamdfir/sift-cli

  • @benney25
    @benney25 3 роки тому

    intro is super loud relative to the content, be careful if wearing headphones

    • @13Cubed
      @13Cubed  3 роки тому +1

      Yeah sorry about that -- much better/different in newer episodes.

  • @majidjahangeer181
    @majidjahangeer181 5 років тому

    Can you please comment the link for images?

    • @13Cubed
      @13Cubed  5 років тому +1

      The memory images used here are not publicly available. However, the "Pulling Threads" episode within this series (ua-cam.com/video/gxA2gjCQs-o/v-deo.html) does have a memory sample you can download and use to follow along (you'll find the link in that episode's description).