Re: [Vol-users] Volatility's Network Connections
by david@sharpebusinesssolutions.com
The Volatility connscan and connscan2 output are identical byte-for-byte against the dump I am talking about. "Connections" terminates gracefully with no console output in tcb_connections in network.py after having trouble locating the right data structure to walk in my dump file.
Thank you for taking the time to respond. I wasn't really asking for help with anything in my initial reply to this thread. I was just trying to support the original author's assertion that there are differences between the various commercial and non-commercial solutions in the Windows memory dump analysis space. In my view, all three that I personally have experience with so far: Volatility, HBGary Responder, and Mandiant Memoryze all have their own strengths and weaknesses. I see this space just like hard drive or mobile device forensics - each of the leading vendors has their strong points and sometimes you need to combine the results of multiple tools to get the best results.
-- David
--- taosecurity(a)gmail.com wrote:
From: Richard Bejtlich <taosecurity(a)gmail.com>
To: david(a)sharpebusinesssolutions.com
Cc: "Don C. Weber" <cutaway(a)cutawaysecurity.com>, vol-users(a)volatilesystems.com
Subject: Re: [Vol-users] Volatility's Network Connections
Date: Mon, 11 May 2009 10:15:48 -0400
On Thu, May 7, 2009 at 10:12 AM, <david(a)sharpebusinesssolutions.com> wrote:
>
>
> I concur with your point about needing to use all three tools. Each has its own strengths and weaknesses. I use HBGary Responder Pro primarily and fall over to Volatility or Mandiant Memoryze when I come across something HBGary can't do (or I don't know how to do in HBGary).
>
> To your point about analyzing network connections, I have recently observed cases where Volatility "connections" produces no output at all and HBGary does. In that situation Volatility "connscan" does find connections, but the lists doesn't 100% match HBGary.
>
Hi David,
When you say "connscan", have you also used "connscan2"?
Thank you,
Richard
_______________________________________________
Vol-users mailing list
Vol-users(a)volatilesystems.com
http://lists.volatilesystems.com/mailman/listinfo/vol-users