On May 7, 2009, at 10:12 AM, "" <david(a)sharpebusinesssolutions.com>
<david(a)sharpebusinesssolutions.com> wrote:
To your point about analyzing network connections, I have recently
observed cases where Volatility "connections" produces no output at
all and HBGary does. In that situation Volatility "connscan" does
find connections, but the lists doesn't 100% match HBGary.
I made a post on Don's blog theorizing about why this might be the case:
http://www.cutawaysecurity.com/blog/archives/523/comment-
page-1#comment-31116
Basically, it comes down to the difference between connections and
connscan2. Also, if sockets or connections returns no output, you may
need to try the SVN version -- one of the post-SP3 hotfixes broke our
ability to examine sockets and connections, and we had to add a new
set of offsets to fix it.
As always, if you find it doesn't work on an XP image, please let us
know so we can fix it :)
I am also a little concerned about what appears to me
to be a drop
in development activity around Volatility. Is Mandiant Memoryze
going to take over the top slot? Right now, I see Mandiant
Memoryze as third best behind HBGary and Volatility, but Volatility
can't stand still.
I don't think there's been a drop in development activity. It's been
a while since our last release, but a lot of activity has been taking
place in the world of Volatility plugins. Andreas Schuster has
recently released several new plugins that can find some less well-
known artifacts of malware, and Jesse Kornblum has released a
Volatility plugin to search memory for TrueCrypt passphrases.
I've also released a set of plugins for examining registry data, and
shown how to integrate with other popular tools like RegRipper. I'm
also working on some plugins that let you look at the state of on-
screen graphical elements like windows, buttons, etc.
For example, does anyone know if there any plans to
provide
functionaility similar to HBGary's new Digital DNA in Volatility?
I don't have any plans to do it myself, but Volatility would provide
an excellent platform to anyone who wanted to build it :)
Cheers,
Brendan
If anyone wants to share information or experiences
across all
three applications or memory dump analysis in general, feel free to
contact me at david(a)sharpebusinesssolutions.com.
-- David
--- cutaway(a)cutawaysecurity.com wrote:
From: "Don C. Weber" <cutaway(a)cutawaysecurity.com>
To: vol-users(a)volatilityfoundation.org
Subject: [Vol-users] Volatility's Network Connections
Date: Wed, 6 May 2009 08:48:47 -0500
I wanted to let you know that while using Volatility and several
other
memory analysis tools I received some conflicting information
associated with
network connections. I did a quick blog post on the subject that
can be read
here:
http://www.cutawaysecurity.com/blog/archives/523 . It looks
like
Volatility shows more information than the others in some instances.
Also, if you have additional information or detail on this
please post a
comment or let me know so that I can add an update to the post.
--
--------------------------
Don C. Weber
Information Security Consultant
Cutaway Security
CISSP, GIAC
#########################################
Website:
http://www.cutawaysecurity.com
_______________________________________________
Vol-users mailing list
Vol-users(a)volatilityfoundation.org
http://lists.volatilityfoundation.org/mailman/listinfo/vol-users
_______________________________________________
Vol-users mailing list
Vol-users(a)volatilityfoundation.org
http://lists.volatilityfoundation.org/mailman/listinfo/vol-users