| jessekornblum ( @ 2007-01-06 12:22:00 |
| Entry tags: | forensics, hacking |
Five Sample Windows Memory Images
Windows memory analysis hit the big time during with 2005 DFRWS Memory Analysis Challenge. A lot of great work has been done since then, but for the most part has been limited to Windows 2000 systems. I believe that part of that limitation stemmed from the lack of memory images from other operating systems. It's hard to make a point about Windows XP memory images when there's no image that everybody shares.
That's why Brian Carrier and I have published five new Windows memory images for academics, tool developers, and practitioners to work with. Three of them come from a standalone machine with 1GB of RAM running Windows 2000, Windows 2003, and Windows Vista Beta 2. The other two images both come a laptop running Windows XP. To my knowledge, none of these machines had any kind of malicious software running on them. Enjoy!