SECURITY 563SECURITY 563


Course PDF

In some cases it may be desirable to find information stored in memory on mobile devices that is no longer accessible logically, particularly deleted data. The fourth day of the course focuses on forensic examination and analysis of full physical memory dumps extracted from mobile devices.

Acquiring full memory contents is one the more challenging aspects of mobile device forensics, and may not be feasible in all cases. We demonstrate the various mechanisms for acquiring memory, including Flasher boxes, and we assess their strengths and limitations from a forensic perspective. We will step you through the process of acquiring the full contents of physical memory from a mobile device. In addition, we will inspect the resulting output with an eye to assessing its completeness and accuracy.

Later in day 4, we guide you through a series of hands-on exercises to teach forensic examination of physical memory in mobile devices. These exercises begin with locating and interpreting data previously observed in logical examination to confirm the accuracy and completeness of findings. We then teach you how to use various tools and techniques for salvaging data from a mobile device memory dump, and confirming key findings by examining them in their original context in hexadecimal form.




SECURITY 563 Upcoming Events
Event Location Dates Delivery Method
SANS Security East 2010New Orleans, LAJan 10, 2010 - Jan 18, 2010Live Event
Community SANS San Antonio 2010San Antonio, TXJan 25, 2010 - Jan 29, 2010Community SANS
SANS Security West 2010San Diego, CAMay 07, 2010 - May 15, 2010Live Event
"This is awsome! We're seeing details that most people don't even know exist" - John Wright, Info Tech, Inc.
"The class provided in-depth, real world, hands-on information" - Robert Dale Drollinger, General Dynamics
SANS Institute