Journal of Computers, Vol 4, No 1 (2009), 3-10, Jan 2009
doi:10.4304/jcp.4.1.3-10

Collecting Sensitive Information from Windows Physical Memory

Qian Zhao, Tianjie Cao

Abstract


When investigators are faced with a target system, they want to find sensitive information such as userID and password. Unfortunately, sensitive information can not be found on the hard drive in most cases. Consequently, sensitive information needs to be gathered from physical memory. In our research, we have found lots of sensitive information from physical memory by different techniques. Besides userID and password, we also have found QQ-chat logs that never have been referred in other papers.



Keywords


memory forensics; sensitive information; live system

References



Full Text: PDF


Journal of Computers (JCP, ISSN 1796-203X)

Copyright @ 2006-2011 by ACADEMY PUBLISHER – All rights reserved.