Gadgets, Games, Software, News -Techno Nerd

A media blog about gadgets, media, software, and technology.

September, 2011

Accessing Volatile Data (3)

Key questions investigators must ask themselves include: Given the situation, will the case investigation benefit from the capture of physical memory? and Can I capture this information in a least-intrusive manner? Armed with the answers to these questions and an understanding of the effects on the evidence made by their action and tools, investigators can [...]

Tags: , , ,

Posted in Computer, Knowledge, Tips | No Comments »

Accessing Volatile Data (2)

Tribble is a hardware expansion card design to reliably acquire the volatile memory of a live system. Acquired memory is captured and extracted to a removable storage system. The hardware device accesses memory directly, and because it does not require software to be loaded, it overwrites possible evidence.

Tags: , , ,

Posted in Computer, Knowledge, Tips | No Comments »

Accessing Volatile Data

When accessing volatile memory one of the first things a computer forensics investigator may recall is the basic scientific principle that the very act of observing something changes it. Certainly there is no exception to this principle in the case of accessing volatile memory.

Tags: , , ,

Posted in Computer, Knowledge, Tips | No Comments »

Volatile Data in Routers and Appliances (3)

With the system running, the investigator is usually limited to collecting data such as the Secure Audit Log data, which has been logged onto remote devices such as syslog servers. Most network appliance and router devices do provide a physical configuration port (usually a serial connection) from which to run a terminal session.

Tags: , , , ,

Posted in Computer, Knowledge | No Comments »

Volatile Data in Routers and Appliances (2)

A third memory component in Cisco routers, the Non-Volatile RAM (NVRAM), contains the startup configuration files. The BootROM, much like the Complementary Metal Oxide Semiconductor (CMOS) and BIOS of a personal computer, contains code for power-on self-test (POST), IOS loading, and so forth.

Tags: , , , ,

Posted in Computer, Hardware, Knowledge | No Comments »

Want to Get Our Update?

Please enter your email address here:

Total of our subscribers:

Topics