Live Memory Forensics on Android With Volatility

  • Upload
    kasma

  • View
    242

  • Download
    0

Embed Size (px)

Citation preview

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    1/109

    http://www1.informatik.uni-erlangen.de/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    2/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    3/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    4/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    5/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    6/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    7/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    8/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    9/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    10/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    11/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    12/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    13/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    14/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    15/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    16/109

    http://developer.android.com/sdk/index.htmlhttp://code.google.com/p/dalvik/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    17/109

    http://de.wikipedia.org/wiki/GNU_General_Public_Licensehttps://www.volatilesystems.com/default/volatilityhttp://source.android.com/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    18/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    19/109

    http://www.eclipse.org/mat/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    20/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    21/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    22/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    23/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    24/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    25/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    26/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    27/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    28/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    29/109

    http://opensource.samsung.com/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    30/109

    http://code.google.com/p/lime-forensics/downloads/listhttp://forum.xda-developers.com/showthread.php?t=755265http://forum.xda-developers.com/showthread.php?t=1347899http://forum.xda-developers.com/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    31/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    32/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    33/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    34/109

    http://reality.sgiweb.org/davea/dwarf.htmlhttps://code.google.com/p/volatility/wiki/LinuxMemoryForensics
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    35/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    36/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    37/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    38/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    39/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    40/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    41/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    42/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    43/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    44/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    45/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    46/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    47/109

    http://developer.android.com/http://code.google.com/p/dalvik/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    48/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    49/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    50/109

    http://en.wikipedia.org/wiki/Reflection_(computer_programming)
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    51/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    52/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    53/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    54/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    55/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    56/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    57/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    58/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    59/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    60/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    61/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    62/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    63/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    64/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    65/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    66/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    67/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    68/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    69/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    70/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    71/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    72/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    73/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    74/109

    http://code.google.com/p/android-random/downloads/detail?name=axml2xml.plhttp://code.google.com/p/android-random/downloads/detail?name=axml2xml.plhttp://code.google.com/p/android-apktool/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    75/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    76/109

    http://www.whatsapp.com/http://code.google.com/p/k9mail/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    77/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    78/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    79/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    80/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    81/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    82/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    83/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    84/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    85/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    86/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    87/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    88/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    89/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    90/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    91/109

    http://lists.volatilesystems.com/pipermail/vol-dev/2013-January/000198.htmlhttp://lists.volatilesystems.com/pipermail/vol-dev/2013-January/000198.htmlhttp://lists.volatilesystems.com/pipermail/vol-dev/2012-October/000187.htmlhttp://lists.volatilesystems.com/pipermail/vol-dev/2012-October/000187.html
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    92/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    93/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    94/109

    http://developer.android.com/http://developer.android.com/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    95/109

    http://docs.oracle.com/javase/tutorial/http://docs.oracle.com/javase/tutorial/http://c-skills.blogspot.de/2010/08/droid2.htmlhttp://c-skills.blogspot.de/2010/08/droid2.htmlhttp://code.google.com/p/k9mail/http://code.google.com/p/k9mail/http://lime-forensics.googlecode.com/files/LiME_Documentation_1.1.pdfhttp://lime-forensics.googlecode.com/files/LiME_Documentation_1.1.pdfhttp://www.itproportal.com/2012/03/02/25ca8c92-645e-11e1-a090-fefdb24f8a11/http://www.itproportal.com/2012/03/02/25ca8c92-645e-11e1-a090-fefdb24f8a11/https://www.idc.com/getdoc.jsp?containerId=prUS23771812https://www.idc.com/getdoc.jsp?containerId=prUS23771812
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    96/109

    http://en.wikipedia.org/w/index.php?title=Android_(operating_system)&oldid=530060896http://en.wikipedia.org/w/index.php?title=Android_(operating_system)&oldid=530060896http://www.whatsapp.com/http://www.whatsapp.com/https://twitter.com/WhatsApp/status/238680463139565568https://twitter.com/WhatsApp/status/238680463139565568https://code.google.com/p/volatility/https://code.google.com/p/volatility/
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    97/109

    http://en.wikipedia.org/w/index.php?title=Forensic_science&oldid=520203985http://en.wikipedia.org/w/index.php?title=Forensic_science&oldid=520203985http://en.wikipedia.org/w/index.php?title=Data_structure_alignment&oldid=525379887http://en.wikipedia.org/w/index.php?title=Data_structure_alignment&oldid=525379887http://en.wikipedia.org/w/index.php?title=Cross_compiler&oldid=518389473http://en.wikipedia.org/w/index.php?title=Cross_compiler&oldid=518389473http://en.wikipedia.org/w/index.php?title=.bss&oldid=525501314http://en.wikipedia.org/w/index.php?title=.bss&oldid=525501314http://en.wikipedia.org/w/index.php?title=Android_rooting&oldid=528094233http://en.wikipedia.org/w/index.php?title=Android_rooting&oldid=528094233
  • 8/10/2019 Live Memory Forensics on Android With Volatility

    98/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    99/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    100/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    101/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    102/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    103/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    104/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    105/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    106/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    107/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    108/109

  • 8/10/2019 Live Memory Forensics on Android With Volatility

    109/109