Home Contact

M-unition

The Ammunition You Need to Find Evil and Solve Crime

About Us

Welcome to M-unition, the MANDIANT blog. Here we share our insights about the tools we create and use to find evil and solve crime.

Join us at RSA

Written by Jamie Butler

Join Peter Silberman and I at RSA as we present “Advanced Memory Analysis: Battling Malware and Its Protection”.  MANDIANT will also be exhibiting in booth 345 on the show floor. Come by and see our team’s newest creation, MANDIANT Intelligent Response 1.3.

Abstract: A copy of the hard drive used to reveal everything.  Today, malware is more defensive – often packed or encoded to avoid static analysis and equipped with the ability to prevent execution in a debugger or a VM.  Malware can even reside completely in memory and never write to the disk.  Memory analysis is now a requirement for forensic or incident analysis.  Watch as we identify and reconstruct malware using only memory.

Time: Tuesday, April 21, 4:10 pm
Session ID: HT2-107

. 07 Apr 09 | The Whiteboard


Leave a Reply

You must be logged in to post a comment.