TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Thanks for the Memories: Identifying Malware from a Memory Capture

33 点作者 2510c39011c5超过 10 年前

3 条评论

cdnsteve超过 10 年前
Great summary, these types of articles always make me want to learn more about capturing malware. Could you use something like Yara to then write your own ruleset to identify this?
评论 #9135283 未加载
netman21超过 10 年前
There are commercial solutions that look at memory constantly to identify malware. ManTech Cyber Solutions International, Inc. (MCSI)is the division the defense contractor created to house it's HBGary division. Guidance Software, best known for its forensics software, Encase, also does this. But the underlying technology is also based on HBGary.
etep超过 10 年前
Where does the memory capture come from?
评论 #9135058 未加载