Welcome to Scribd. Sign in or start your free trial to enjoy unlimited e-books, audiobooks & documents.Find out more
Download
Standard view
Full view
of .
Look up keyword
Like this
3Activity
0 of .
Results for:
No results containing your search query
P. 1
'Memory Grabber' Forensics Tool (SRA Int'l)

'Memory Grabber' Forensics Tool (SRA Int'l)

Ratings: (0)|Views: 312|Likes:
Published by Impello_Tyrannis
The purpose of this paper is to describe the SRA Memory Grabber system, which provides memory access to a running and password protected laptop through the use of a small PC Card inserted into the PCMCIA slot of the laptop. The Memory Grabber device shown in the figure below is operating system agnostic; working on Microsoft Windows, Linux, and MacOS and is available today as a production unit for use with Express Card and Card Bus laptop systems.
The purpose of this paper is to describe the SRA Memory Grabber system, which provides memory access to a running and password protected laptop through the use of a small PC Card inserted into the PCMCIA slot of the laptop. The Memory Grabber device shown in the figure below is operating system agnostic; working on Microsoft Windows, Linux, and MacOS and is available today as a production unit for use with Express Card and Card Bus laptop systems.

More info:

Published by: Impello_Tyrannis on Apr 10, 2011
Copyright:Attribution Non-commercial

Availability:

Read on Scribd mobile: iPhone, iPad and Android.
download as PDF, TXT or read online from Scribd
See more
See less

12/15/2012

pdf

text

original

 
 
Memory Grabber 
Computer Forensic Volatile Memory Acquisition and Analysis System
White Paper
6 May 2010
Prepared By:
Jim CostabileSystems Research and Applications Corporation8830 Stanford Blvd., Suite 205Columbia, MD 21045jim_costabile@sra.com443-656-7247
SRA authorizes the distribution of this document to registered customers only.No other distribution is authorized without the consent of SRA
SRA PROPRIETARY
 
 
SRA PROPRIETARY
Use or disclosure of data contained on this sheet is subject to the restriction on the title page of this document.
Memory Grabber
SRA PROPRIETARY
 
3
of
7
 
1
0B
INTRODUCTION
1.1
4B
Purpose
The purpose of this paper is to describe the SRA Memory Grabber system, which providesmemory access to a running and password protected laptop through the use of a small PC Cardinserted into the PCMCIA slot of the laptop. The Memory Grabber device shown in the figurebelow is operating system agnostic; working on Microsoft Windows, Linux, and MacOS and isavailable today as a production unit for use with Express Card and Card Bus laptop systems.
Figure 1: Memory Grabber Device
2
1B
OPERATIONAL NEED
2.1
5B
Problem Description
Currently, when law enforcement agents or Special Operations personnel seize a running laptopthat is password protected, they have no way of capturing the potential valuable informationresident in memory. Typically, they will power down the laptop and take it back to lab toperform forensic analysis on the hard drive losing all information associated with the currentstate of the machine (e.g. partially constructed documents or emails, web history, or any otherinformation that gets permanently deleted upon power down). Law enforcement agents andSpecial Operations personnel need a tool that provides memory access to a running laptop in thefield enabling the timely capture of volatile information.

Activity (3)

You've already reviewed this. Edit your review.
1 hundred reads
1 thousand reads

You're Reading a Free Preview

Download
scribd
/*********** DO NOT ALTER ANYTHING BELOW THIS LINE ! ************/ var s_code=s.t();if(s_code)document.write(s_code)//-->