Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts
Monday, May 18, 2015
Linux Memory Forensics: Using mprotect() with PROT_NONE
In case you didn't catch it on the Volatility Labs blog, I found an interesting bug that we've had in the framework since we've had Linux support. If you've had cases that involved Linux samples and plugins like linux_yarascan, linux_strings etc, you might want to update to the latest code and have another look over those samples. Of course, there's no reason to think that a piece of malware might have used this trick and used a sigsegv handler to access the data, but the idea has been around for years...
Labels:
linux,
malware,
memory,
volatility
Monday, April 14, 2014
Volatility Talk at Upcoming NYC4SEC
The Volatility team will give a talk at the next NYC4SEC meetup on memory forensics on May 8th, 2014 at John Jay College. Make sure to RSVP if you are planning to attend, since there is limited seating!
Thanks For the Memory: Rootkits, Exfil and APT - RAM Conquers All
The ability to perform digital investigations and incident response is becoming a critical skill for many occupations. Unfortunately, digital investigators frequently lack the training or experience to take advantage of the volatile artifacts found in physical memory. Volatile memory contains valuable information about the runtime state of the system, provides the ability to link artifacts from traditional forensic analysis (network, file system, registry), and provides the ability to ascertain investigative leads that have been unbeknownst to most analysts. Malicious adversaries have been leveraging this knowledge disparity to undermine many aspects of the digital investigation process with such things as anti-forensics techniques, memory resident malware, kernel rootkits, encryption (file systems, network traffic, etc), and Trojan defenses. The only way to turn-the-tables and defeat a creative digital human adversary is through talented analysts.
This talk demonstrates the importance of including Volatile memory in your investigations with an overview of the most widely used memory forensics tool, Volatility, by its developers.
-@gleeda
Thanks For the Memory: Rootkits, Exfil and APT - RAM Conquers All
The ability to perform digital investigations and incident response is becoming a critical skill for many occupations. Unfortunately, digital investigators frequently lack the training or experience to take advantage of the volatile artifacts found in physical memory. Volatile memory contains valuable information about the runtime state of the system, provides the ability to link artifacts from traditional forensic analysis (network, file system, registry), and provides the ability to ascertain investigative leads that have been unbeknownst to most analysts. Malicious adversaries have been leveraging this knowledge disparity to undermine many aspects of the digital investigation process with such things as anti-forensics techniques, memory resident malware, kernel rootkits, encryption (file systems, network traffic, etc), and Trojan defenses. The only way to turn-the-tables and defeat a creative digital human adversary is through talented analysts.
This talk demonstrates the importance of including Volatile memory in your investigations with an overview of the most widely used memory forensics tool, Volatility, by its developers.
-@gleeda
Friday, February 07, 2014
New Volatility Training Website
We have a new website for all of our Volatility training opportunities. Don't forget to check it out: http://www.memoryanalysis.net/
- @gleeda
- @gleeda
Labels:
forensics,
malware,
memory,
training,
volatility
Tuesday, July 16, 2013
Volatility News
Things have been busy lately, but I want to let you know about some important items that are coming up quickly:
Andrew Case and I will teach our course in Digital Forensics and Incident Response again this summer at Black Hat Vegas. This course will cover enough material to take someone from knowing practically nothing about digital forensics (disk and memory) to a point where s/he can comfortably conduct his/her own investigations. There is limited time to sign up, so reserve your seat while you can!
You can hear Andrew talk about Digital Forensics and Incident Response on the Healthy Paranoia podcast from July 7th, 2013.
The 1st Annual Volatility Plugin Contest deadline is quickly approaching! Don't miss this opportunity to win over $2000 in cash and prizes and contribute to the top memory forensics framework by writing a plugin for the Volatility Framework and submitting it to volcon2013@memoryanalysis.net by August 1st, 2013.
We will have our 4th public offering of our official Windows Malware and Memory Forensics training in the Netherlands September 9-13, 2013. This will be our only offering outside the US for this year. Past offerings of our course have been well received and were recently described as the "... perfect combination of incident response, malware analysis and Windows internals." Don't miss out on your chance to take this course and learn not only how to become a Volatility superuser, but how to apply cutting edge memory and malware analysis methodologies against your worst adversary.
The Open Memory Forensics Workshop (OMFW) call for papers has been announced. If you want to give a talk on memory forensics related topics, please get your submission in by September 1st, 2013. OMFW is a half-day workshop that will be held one day prior to the Open Source Digital Forensics Conference in Chantilly, VA. This workshop is fast-paced, to the point, highly technical and intended to raise the bar for analysts who realize the importance of memory forensics when faced with a highly skilled adversary. Not only will you learn a lot and get to meet all the movers and shakers in the space, but your $50 registration fee is entirely donated to charity! Last year all proceeds went to the National Center for Missing and Exploited Children. So don't delay: there really is limited seating and it does go quickly. Make sure to register your seat now!
The Volatility team will be at the Open Source Digital Forensics Conference discussing The State of Volatility. Come by and see us there :-)
We will have our 5th public offering of the official Windows Malware and Memory Forensics training in Reston, VA November 11-15th, 2013. If you missed the last offering in June, this is your chance to take this course and learn from the developers themselves. As I've stated before, this class includes real-world scenarios that are reinforced with hands-on labs. We cover more than "just one tool" as some detractors like to say. We cover methodologies that will actually help you where some tools fail. You will have a deep enough understanding to investigate even the most skilled adversaries who know how to break common tools in order to hide. Don't be fooled and don't be left behind. Accept no imitations and make sure to take this class.
All students who take the official Volatility training receive a certificate of completion, with CPE credits that can be used for certification renewal. In addition to this, we are constantly updating the course with new material and past students are given updated materials for FREE. What more can you ask for? If you are interested in Volatility training, drop us a line at voltraining [[ at ]] memoryanalysis.net
If you want to see co-trainers MHL and Andrew Case (attrc) in action, I managed to find a couple of videos of their previous talks on youtube:
July 27-30th, 2013: Blackhat Vegas
Andrew Case and I will teach our course in Digital Forensics and Incident Response again this summer at Black Hat Vegas. This course will cover enough material to take someone from knowing practically nothing about digital forensics (disk and memory) to a point where s/he can comfortably conduct his/her own investigations. There is limited time to sign up, so reserve your seat while you can!
You can hear Andrew talk about Digital Forensics and Incident Response on the Healthy Paranoia podcast from July 7th, 2013.
August 1st, 2013: Volatility Plugin Contest
The 1st Annual Volatility Plugin Contest deadline is quickly approaching! Don't miss this opportunity to win over $2000 in cash and prizes and contribute to the top memory forensics framework by writing a plugin for the Volatility Framework and submitting it to volcon2013@memoryanalysis.net by August 1st, 2013.
September 9-13th, 2013: Volatility Training in the Netherlands
We will have our 4th public offering of our official Windows Malware and Memory Forensics training in the Netherlands September 9-13, 2013. This will be our only offering outside the US for this year. Past offerings of our course have been well received and were recently described as the "... perfect combination of incident response, malware analysis and Windows internals." Don't miss out on your chance to take this course and learn not only how to become a Volatility superuser, but how to apply cutting edge memory and malware analysis methodologies against your worst adversary.
November 4th, 2013: Open Memory Forensics Workshop (OMFW)
The Open Memory Forensics Workshop (OMFW) call for papers has been announced. If you want to give a talk on memory forensics related topics, please get your submission in by September 1st, 2013. OMFW is a half-day workshop that will be held one day prior to the Open Source Digital Forensics Conference in Chantilly, VA. This workshop is fast-paced, to the point, highly technical and intended to raise the bar for analysts who realize the importance of memory forensics when faced with a highly skilled adversary. Not only will you learn a lot and get to meet all the movers and shakers in the space, but your $50 registration fee is entirely donated to charity! Last year all proceeds went to the National Center for Missing and Exploited Children. So don't delay: there really is limited seating and it does go quickly. Make sure to register your seat now!
November 5th, 2013: Open Source Digital Forensics Conference
The Volatility team will be at the Open Source Digital Forensics Conference discussing The State of Volatility. Come by and see us there :-)
November 11-15th, 2013: Volatility Training in Reston, VA
We will have our 5th public offering of the official Windows Malware and Memory Forensics training in Reston, VA November 11-15th, 2013. If you missed the last offering in June, this is your chance to take this course and learn from the developers themselves. As I've stated before, this class includes real-world scenarios that are reinforced with hands-on labs. We cover more than "just one tool" as some detractors like to say. We cover methodologies that will actually help you where some tools fail. You will have a deep enough understanding to investigate even the most skilled adversaries who know how to break common tools in order to hide. Don't be fooled and don't be left behind. Accept no imitations and make sure to take this class.
All students who take the official Volatility training receive a certificate of completion, with CPE credits that can be used for certification renewal. In addition to this, we are constantly updating the course with new material and past students are given updated materials for FREE. What more can you ask for? If you are interested in Volatility training, drop us a line at voltraining [[ at ]] memoryanalysis.net
If you want to see co-trainers MHL and Andrew Case (attrc) in action, I managed to find a couple of videos of their previous talks on youtube:
Labels:
blackhat vegas,
conferences,
forensics,
malware,
memory,
news,
OMFW,
plugins,
talks,
travel,
volatility,
windows
Friday, April 19, 2013
Upcoming Events and Trainings
I have several speaking and training events that are coming up this year that may be of interest to others in the community:
I will be speaking at the New York Banker's Association's upcoming Annual Technology, Compliance & Risk Management Forum on May 16th, 2013 on the topic of Incident Response and Digital Forensics. If you plan to attend I'll see you there!
Also we (Volatility) are holding our third run of Windows Malware and Memory Forensics in Reston, VA from Monday June 10th through Friday, June 14th 2013. This training will not disappoint even the most proficient of forensic/malware analysts. It includes real-world scenarios that are reinforced with hands-on labs. All students will leave with skills and confidence to conduct investigations involving RAM samples from acquisition to the final report. Students also leave with more than just being Volatility power users, they leave with a deeper knowledge of memory forensics and malware analysis methodologies. Such knowledge is integral regardless of what tools you choose for future investigations, be they open source or commercial, and much more powerful than simply "run this tool, the output is colored red so it's bad". You'll leave the class with knowledge that will help you to figure out if something really is "bad" or not. There are still a few seats left for this training, so if you are interested you should register soon. Send an email to voltraining [at] memoryanalysis.net for registration information.
If you are looking for a course that covers both disk and memory forensics, Andrew Case and I will teach our course in Digital Forensics and Incident Response again this summer at Black Hat Vegas. This course runs from July 27th through July 30th 2013 and will cover enough material to take someone from knowing practically nothing about digital forensics to a point where s/he can comfortably conduct his/her own investigations.
Also we (Volatility) will hold another run of Windows Malware and Memory Forensics in the Netherlands from Monday September 9th through Friday, September 13th 2013. Details will appear soon on the Volatility Labs blog.
Planning for the Open Memory Forensics Workshop (OMFW) is in progress. You should plan to attend if you want to know what's new and hot in the memory forensics space. OMFW is likely to take place on November 4th, 2013 one day prior to the Sleuth Kit and Open Source Digital Forensics Conference. Final details will appear soon on the Volatility Labs blog.
I will be speaking at the New York Banker's Association's upcoming Annual Technology, Compliance & Risk Management Forum on May 16th, 2013 on the topic of Incident Response and Digital Forensics. If you plan to attend I'll see you there!
Also we (Volatility) are holding our third run of Windows Malware and Memory Forensics in Reston, VA from Monday June 10th through Friday, June 14th 2013. This training will not disappoint even the most proficient of forensic/malware analysts. It includes real-world scenarios that are reinforced with hands-on labs. All students will leave with skills and confidence to conduct investigations involving RAM samples from acquisition to the final report. Students also leave with more than just being Volatility power users, they leave with a deeper knowledge of memory forensics and malware analysis methodologies. Such knowledge is integral regardless of what tools you choose for future investigations, be they open source or commercial, and much more powerful than simply "run this tool, the output is colored red so it's bad". You'll leave the class with knowledge that will help you to figure out if something really is "bad" or not. There are still a few seats left for this training, so if you are interested you should register soon. Send an email to voltraining [at] memoryanalysis.net for registration information.
If you are looking for a course that covers both disk and memory forensics, Andrew Case and I will teach our course in Digital Forensics and Incident Response again this summer at Black Hat Vegas. This course runs from July 27th through July 30th 2013 and will cover enough material to take someone from knowing practically nothing about digital forensics to a point where s/he can comfortably conduct his/her own investigations.
Also we (Volatility) will hold another run of Windows Malware and Memory Forensics in the Netherlands from Monday September 9th through Friday, September 13th 2013. Details will appear soon on the Volatility Labs blog.
Planning for the Open Memory Forensics Workshop (OMFW) is in progress. You should plan to attend if you want to know what's new and hot in the memory forensics space. OMFW is likely to take place on November 4th, 2013 one day prior to the Sleuth Kit and Open Source Digital Forensics Conference. Final details will appear soon on the Volatility Labs blog.
Labels:
blackhat vegas,
conferences,
forensics,
malware,
memory,
OMFW,
talks,
training,
volatility,
windows
Monday, January 14, 2013
Windows Malware and Memory Forensics Training in The Windy City!
Cross posted from the Volatility Labs Blog:
The next journey to the center of Windows Memory Forensics starts in Chicago this March!
We are pleased to announce the second public offering of the Windows Malware and Memory Forensics Training by The Volatility Project. This is the only memory forensics course officially designed, sponsored, and taught by the Volatility developers. One of the main reasons we made Volatility open-source is to encourage and facilitate a deeper understanding of how memory analysis works, where the evidence originates, and how to interpret the data collected by the framework's extensive set of plugins. Now you can learn about these benefits first hand from the developers of the most powerful, flexible, and innovative memory forensics tool.
Appraisal from your peers who attended the first course this past December:
Please see the following details about the upcoming training event:
Dates: Monday, March 18th through Friday, March 22nd 2013
Location: Downtown Chicago, IL (exact location will be shared upon registration)
Instructors: Michael Ligh (@iMHLv2), Andrew Case (@attrc), Jamie Levy (@gleeda)
For more information about the course, view the Volatility Training Flyer (to download a copy of the PDF, click File > Download). To request a link to the online registration site or to receive a detailed course agenda/outline, please send an email voltraining [at] memoryanalysis.net.
Saturday, September 29, 2012
Week 3 of the Month of Volatility Plugins posted!
Cross listed from Andrew Case's blog:
I was writing to announce that week 3 of the month of Volatility plugins is finished, and we now have five more in-depth blog posts covering Windows and Linux internals and rootkit detection as well as a bonus plugin that analyzes Internet Explorer browsing history. These have all been posted on the Volatility Labs blog.
Post 1: Detecting Malware Hooks in the Windows GUI Subsystem
This Windows focused post covers detecting malware hooks in the Windows GUI subsystem, including message hooks and event hooks, and what effects these hooks can have on a compromised system.
http://volatility-labs.blogspot.com/2012/09/movp-31-detecting-malware-hooks-in.html
Post 2: Shellbags in Memory, SetRegTime, and TrueCrypt Volumes
This Windows focused post covers finding and recovering shellbags from memory, the forensics importance of shellbags, and analyzes the effects of anti-forensics on shellbag timestamps. It concludes with covering the traces left in shellbags by TrueCrypt.
http://volatility-labs.blogspot.com/2012/09/movp-32-shellbags-in-memory-setregtime.html
Post 3: Analyzing USER Handles and the Win32k.sys Gahti
This Windows focused post introduces two new plugins, one named gahti that determines the various different types of USER objects on a system and another named userhandles which traverses the handle table entries and associates them with the owning processes or threads
http://volatility-labs.blogspot.com/2012/09/movp-33-analyzing-user-handles-and.html
Post 4: Recovering tagCLIPDATA: What's In Your Clipboard?
This Windows focused post covers recovery of the Windows clipboard from physical memory.
http://volatility-labs.blogspot.com/2012/09/movp-34-recovering-tagclipdata-whats-in.html
Post 5: Analyzing the 2008 DFRWS Challenge with Volatility
This Linux focused post analyzes the 2008 memory challenge with Volatility. It walks through the artifacts produced by the winning team and shows how to recover the same information with Volatility. It then shows plugins in Volatility that can recover artifacts not produced by the winning team.
http://volatility-labs.blogspot.com/2012/09/movp-35-analyzing-2008-dfrws-challenge.html
Bonus Post: HowTo: Scan for Internet Cache/History and URLs
This Windows focused post covers how to recover Internet Explorer's cache and history from a memory sample.
http://volatility-labs.blogspot.com/2012/09/howto-scan-for-internet-cachehistory.html
If you have any questions or comments on the posts, please leave a comment on the respective post on the Volatility Labs blog.
Friday, September 21, 2012
Week 2 of the Month of Volatility Plugins posted!
It's been an exciting week in the Volatility community. We've just finished our second week of Month of Volatility Plugins (MoVP) blogposts, released Volatility 2.2 RC2 for testing, fixed a few minor bugs and now we're gearing up for our third week of posts and the upcoming Open Memory Forensics Workshop (OMFW). Here is a list of this week's posts, compiled by Andrew Case:
We hope you've enjoyed this week's series. Stay tuned, we have much more in store!
I was writing to announce that week 2 of the month of Volatility plugins is finished, and we now have five more in-depth blog posts covering Windows and Linux internals and rootkit detection. These have all been posted to the new Volatility Labs blog.
Post 1: Atoms (The New Mutex), Classes and DLL Injection
This Windows focused post covers investigating malware and understanding infections by analyzing the atom tables.
http://volatility-labs.blogspot.com/2012/09/movp-21-atoms-new-mutex-classes-and-dll.html
Post 2: Malware in your Windows
This Windows focused post covers enumerating and analyzing windows in the GUI subsystem.
http://volatility-labs.blogspot.com/2012/09/movp-22-malware-in-your-windows.html
Post 3: Event logs and Service SIDs
This Windows focused post demonstrates recovering event logs from memory and calculating service SIDs.
http://volatility-labs.blogspot.com/2012/09/movp-23-event-logs-and-service-sids.html
Post 4: Analyzing the Jynx rootkit and LD_PRELOAD
This Linux focused post covers analyzing the Jynx rootkit as well as generic methods for analyzing LD_PRELOAD based rootkits.
http://volatility-labs.blogspot.com/2012/09/movp-24-analyzing-jynx-rootkit-and.html
Post 5: Investigating In-Memory Network Data with Volatility
This Linux focused post goes through each of the Linux Volatility plugins related to recovering network data from memory, such as network connections, packets, and the routing cache.
http://volatility-labs.blogspot.com/2012/09/movp-25-investigating-in-memory-network.html
If you have any questions or comments on the posts, please leave a comment on the respective post on the Volatility Labs blog.
We hope you've enjoyed this week's series. Stay tuned, we have much more in store!
Friday, September 14, 2012
Week 1 of the Month of Volatility Plugins posted!
I'm going to borrow from Andrew's blog here to let you know about our Month of Volatility Plugins:
Future Volatility posts will appear on our official blog (http://volatility-labs.blogspot.com/). Also you might want to follow our project on twitter: @Volatility for updates and news. See you at OMFW!
I was writing to announce that week 1 of the month of Volatility plugins is finished, and we now have five in-depth blog posts covering Windows and Linux internals and rootkit detection. These have all been posted to the new Volatility Labs blog.
Post 1: Logon Sessions, Processes, and Images
This Windows focused post covers linking processes to their logon session, detecting hidden processes using session structures, and determining the loaded the drivers mapped into each session.
http://volatility-labs.blogspot.com/2012/09/movp-11- logon-sessions-processes-and. html
Post 2: Window Stations and Clipboard Malware
This Windows focused post covers enumerating and analyzing window stations and clipboard monitoring malware.
http://volatility-labs.blogspot.com/2012/09/movp-12- window-stations-and-clipboard. html
Post 3: Desktops, Heaps, and Ransomware
This Windows focused post covers finding rogue desktops used to hide applications and created by ransomware, linking threads to desktops, analyzing the desktop heap for memory corruptions, and profiling heap allocations to locate USER objects.
http://volatility-labs.blogspot.com/2012/09/movp-13- desktops-heaps-and-ransomware. html
Post 4: Average Coder Rootkit, Bash History, and Elevated Processes
This Linux focused post covers analyzing the Average Coder rootkit, recovering .bash_history from memory, even when faced with anti-forensics, and finding elevated processes.
http://volatility-labs.blogspot.com/2012/09/movp-14- average-coder-rootkit-bash. html
Post 5: KBeast Rootkit, Detecting Hidden Modules, and sysfs
This Linux focused post covers analyzing the KBeast rootkit, finding modules unlinked from the module list, and the forensic values of sysfs.
http://volatility-labs.blogspot.com/2012/09/movp-15- kbeast-rootkit-detecting- hidden.html
If you have any questions or comments on the posts, please leave a comment on the respective post on the Volatility Labs blog.
Future Volatility posts will appear on our official blog (http://volatility-labs.blogspot.com/). Also you might want to follow our project on twitter: @Volatility for updates and news. See you at OMFW!
Labels:
malware,
memory,
OMFW,
plugins,
volatility
Subscribe to:
Posts (Atom)
