Forensic reconstruction of executables from Windows 7 physical memory

S Dija, G S Suma, Dagma D Gonsalvez, Arun T Pillai · 2016

Memory Forensics becomes indispensable in Cyber Forensics Investigation as Random Access Memory or Physical Memory of a Computer holds crucial evidence which is nowhere available on Hard Disks or in other non-volatile storage media. This is because, nowadays most of the malwares are memory resident which leaves no footprints in Hard Disk storage. In this paper, a novel methodology is described for efficiently reconstructing executables from memory dumps acquired from ×86 and ×64 Windows 7 systems. This reconstruction process is challenging because different sections of the executables reside in different memory pages and thus in different locations in the acquired memory dump file. The reconstructed executables may provide crucial information in a cyber crime investigation, especially in the case of malware based crimes. The same methodology can be extended for recovering packed malware executables.

Read the paper · More papers on PaperTik