Автор: Dmitry Vostokov
Издательство: Leanpub/OpenTask
Год: 2022-10-22 (Revision 3)
Страниц: 97
Язык: английский
Формат: pdf (true)
Размер: 10.2 MB
This short book is a fully revised transcript of a lecture introducing a pattern language for memory forensics - an investigation of past software behavior in memory snapshots. It provides a unified language for discussing and communicating detection and analysis results despite the proliferation of operating systems and tools, a base language for checklists, and aid in accelerated learning. The lecture has a short theoretical part and then illustrates various patterns seen in crash dumps by using WinDbg debugger from Microsoft Debugging Tools for Windows. Memory forensics is a part of software forensics that considers many types of software execution artifacts and not only memory snapshots.
Скачать Pattern-Oriented Memory Forensics : A Pattern Language Approach, Revised Edition