NUST Institutional Repository

Forensics Analysis of Windows 8.1 Physical Memory

Show simple item record

dc.contributor.author Ahmed, Waqas
dc.contributor.author Supervised by Dr. Baber Aslam.
dc.date.accessioned 2020-10-26T07:06:37Z
dc.date.available 2020-10-26T07:06:37Z
dc.date.issued 2016-05
dc.identifier.other TIS-200
dc.identifier.other MSIS-11
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/4907
dc.description.abstract Memory forensic analysis is an important component of digital forensic and plays critical role in investigation of any digital crime. Volatile memory contains wealth of important information regarding current state of system. Memory forensics techniques examine RAM images to extract variety of artifacts including sensitive information such as password, email messages, encryption keys etc. This information can help investigators to reconstruct the critical events surrounding criminal use of digital devices and other information technology resources. This research work presents Windows memory forensics analysis using multiple scenarios, which delivers useful ideas to digital investigators, malware analyst and researchers. Each scenario provides examination of critical Windows artifacts that are available in physical memory. A state of the art analysis work on Windows physical memory acquisition tools assist investigators and first responders to select most appropriate acquisition tool to complete successful memory acquisition phase. Comparison of different Windows version for running processes in memory gives useful information and plays vital role in memory forensics research and development. Moreover, Windows page file analysis presents Windows behavior to manage page file and sensitive information. en_US
dc.language.iso en en_US
dc.publisher MCS en_US
dc.title Forensics Analysis of Windows 8.1 Physical Memory en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account