Librenix
Headlines | Linux | Apps | Coding | BSD | Admin | News
Information for Linux System Administration 

Linux Memory Forensics

Up
vote
Down

Examining memory for security clues...
There are three main areas from which evidence of an intrusion can be gathered. The first and most common is the hard drive. A file system on a hard drive contains the least volatile data. Whether the investigator's strategy involves shutting down the system or just removing the computer's power, the file system will still be there. The investigator's response strategy will dictate what changes are made to the file system. If the file system is shut down or if the investigator issues commands to the system to collect information, the file system may be changed, but in the end, it's still there. There are then many tools, such as The Sleuth Kit or The Coroner's Toolkit (TCT), that can be used to analyze the file system.
 read more | mail this link | score:7560 | -Ray, March 19, 2004
More Sysadmin articles...

Colorful Abstract Art

admin headlines

Tutorial: Install Lighttpd, PHP5, MySQL on OpenSUSE 12.2

Tutorial: Install Apache2 with PHP5 and MySQL on CentOS 6.3

Choosing a Tool to Monitor Your Network

Tutorial: Run ownCloud3 on Nginx on Debian 6, Ubuntu 11.10

Tutorial: WordPress, Nginx (LEMP) on Debian 6/Ubuntu 11.04

Tutorial: Build a CentOS 6.0 x86_64 server

 

Firefox sidebar

Site map

Site info

News feed

Features

Login
(to post)

Search

 
Articles are owned by their authors.   © 2000-2012 Ray Yeargin