{"id":7972,"date":"2014-10-30T20:41:48","date_gmt":"2014-10-30T23:41:48","guid":{"rendered":"http:\/\/www.ethicalhacker.com.br\/site\/?p=7972"},"modified":"2019-06-18T17:42:42","modified_gmt":"2019-06-18T20:42:42","slug":"volatility-framework-2-1-analisando-dump-de-memoria","status":"publish","type":"post","link":"https:\/\/www.ethicalhacker.com.br\/site\/2014\/10\/basico\/volatility-framework-2-1-analisando-dump-de-memoria\/","title":{"rendered":"Volatility Framework 2.1- Analisando DUMP de mem\u00f3ria"},"content":{"rendered":"<p>Ol\u00e1 pessoal, neste pequeno artigo mostro como executar um dump de mem\u00f3ria e ap\u00f3s analis\u00e1-lo com a ferramenta forense (Volatility Framework 2.1) contida no Kali Linux.<\/p>\n<p>Antes de tudo, voc\u00ea deve efetuar o dump de mem\u00f3ria &#8230;para isto, voc\u00ea pode utilizar a\u00a0 ferramenta FTK Imager, no caso deste \u00a0laborat\u00f3rio &#8230; executei o dump em uma m\u00e1quina XP PRO.<\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/146.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7973\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/146-300x207.png\"  alt=\"1\" width=\"300\" height=\"207\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/146-300x207.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/146.png 749w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Ap\u00f3s a extra\u00e7\u00e3o do dump, basta copi\u00e1-lo \u00a0para o Kali Linux.<\/p>\n<p>Efetuando as primeira an\u00e1lises &#8230;<\/p>\n<p>Voc\u00ea pode obter ajuda atrav\u00e9s do comando:<\/p>\n<p><strong>root@kali:~# vol -h<\/strong><\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Obtendo informa\u00e7\u00f5es sobre a imagem:<\/p>\n<p><strong>root@kali:~# vol -f \/root\/Desktop\/memdump.mem imageinfo<\/strong><\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/228.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7974\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/228-300x104.png\"  alt=\"2\" width=\"300\" height=\"104\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/228-300x104.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/228.png 833w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u00a0<\/strong>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Verificando processos em execu\u00e7\u00e3o:<\/p>\n<p><strong>root@kali:~# vol -f \/root\/Desktop\/memdump.mem pslist<\/strong><\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/323.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7975\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/323-300x122.png\"  alt=\"3\" width=\"300\" height=\"122\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/323-300x122.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/323.png 963w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Verificando aloca\u00e7\u00e3o de mem\u00f3ria por processos:<\/p>\n<p><strong>root@kali:~# vol -f \/root\/Desktop\/memdump.mem psscan<\/strong><\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/422.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7976\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/422-300x101.png\"  alt=\"4\" width=\"300\" height=\"101\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/422-300x101.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/422.png 799w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Verificando SID de usu\u00e1rios:<\/p>\n<p><strong>root@kali:~# vol -f \/root\/Desktop\/memdump.mem getsids<\/strong><\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/521.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7977\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/521-300x191.png\"  alt=\"5\" width=\"300\" height=\"191\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/521-300x191.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/521.png 578w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Verificando buscando por DLL:<\/p>\n<p><strong>root@kali:~# vol -f \/root\/Desktop\/memdump.mem dlllist<\/strong><\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/616.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7978\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/616-300x203.png\"  alt=\"6\" width=\"300\" height=\"203\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/616-300x203.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/616.png 795w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Verificando conex\u00f5es ativas:<\/p>\n<p><strong>root@kali:~# vol -f \/root\/Desktop\/memdump.mem connections<\/strong><\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/716.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7979\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/716-300x114.png\"  alt=\"7\" width=\"300\" height=\"114\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/716-300x114.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/716.png 731w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Verificando conex\u00f5es finalizadas<\/p>\n<p><strong>root@kali:~# vol -f \/root\/Desktop\/memdump.mem connscan<\/strong><\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/810.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7980\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/810-300x65.png\"  alt=\"8\" width=\"300\" height=\"65\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/810-300x65.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/810.png 681w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>E isso ai &#8230; at\u00e9 a pr\u00f3xima !!!<\/p>\n\r\n\t\t<div class='author-shortcodes'>\r\n\t\t\t<div class='author-inner'>\r\n\t\t\t\t<div class='author-image'>\r\n\t\t\t<img src='https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/186048_100001838322519_1550894_n-11668_57x57.jpg' alt='' \/>\r\n\t\t\t<div class='author-overlay'><\/div>\r\n\t\t<\/div> <!-- .author-image --> \r\n\t\t<div class='author-info'>\r\n\t\t\t<p>Autor: S\u00edlvio C\u00e9sar Roxo Giavaroto<\/p>\n<p>\u00c9 MBA Especialista em Gest\u00e3o de Seguran\u00e7a da Informa\u00e7\u00e3o,<\/p>\n<p>Tecn\u00f3logo em Redes de Computadores, C|EH Certified Ethical Hacker,<\/p>\n<p>atua como Pentest e Analista de Seguran\u00e7a em Servidores Linux no<\/p>\n<p>Governo do Estado de S\u00e3o Paulo, Professor Universit\u00e1rio , Instrutor<\/p>\n<p>C|EH e C|HFI.<\/p>\r\n\t\t<\/div> <!-- .author-info --><\/p>\r\n\t\t\t<\/div> <!-- .author-inner -->\r\n\t\t<\/div> <!-- .author-shortcodes -->\n<p><strong style=\"font-size: 13px;\">\u00a0<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ol\u00e1 pessoal, neste pequeno artigo mostro como executar um dump de mem\u00f3ria e ap\u00f3s analis\u00e1-lo com a ferramenta forense (Volatility Framework 2.1) contida no Kali Linux. Antes de tudo, voc\u00ea deve efetuar o dump de mem\u00f3ria &#8230;para isto, voc\u00ea pode utilizar a\u00a0 ferramenta FTK Imager, no caso deste \u00a0laborat\u00f3rio &#8230; executei o dump em uma [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7982,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[89,100],"tags":[],"class_list":["post-7972","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-basico","category-diversos"],"_links":{"self":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/7972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/comments?post=7972"}],"version-history":[{"count":3,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/7972\/revisions"}],"predecessor-version":[{"id":7984,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/7972\/revisions\/7984"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media\/7982"}],"wp:attachment":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media?parent=7972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/categories?post=7972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/tags?post=7972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}