iT邦幫忙

2026 iThome 鐵人賽

DAY 9
0
Security

那些留在電腦裡的證據:從零開始認識數位鑑識系列 第 9 篇

[DAY 09] Memory 裡到底在跑什麼?Volatility 2.6 記憶體分析

  • 分享至 

  • xImage
  •  

今天實作經典的 Memory Forensics 工具 Volatility 2.6。

Volatility 是一套開源的記憶體取證分析工具,使用 python 編寫成,以命令提示字元操作,可以從 Memory Dump 中解析出 Process、Network Connection、Registry、Command History 等資訊。

簡單來說,前幾天比較像是在問:

Memory 裡留下了哪些資料?

今天則開始問:

Capture Memory 的那一刻,系統到底在執行什麼?連到哪裡?又留下哪些系統資訊?

Volatility 2.6 已經是比較舊的版本,對較新的 Windows 版本支援有限;後面也會再使用 Volatility 3。今天先從 2.6 開始,因為很多經典的 Memory Forensics 教材與舊 Memory Image 都還是使用這個版本。

Volatility2.6 安裝

  1. 下載 Volatility2.6 以及 python (版本2 以上)
  2. 將欲分析的 mem 檔放到 Volatility2.6 資料夾中
    image

volatility2.6 分析記憶體

先在 cmd 中 ls Volatility2.6 資料夾

獲取記憶體的摘要資訊

包含 Suggested profile、Image time 等等
要注意這裡的 time 都是 UTC+0000
Suggested profile 有可能會用到

volatility_2.6_win64_standalone.exe -f [映像檔] imageinfo

image

查看網路狀態

有機會可以找出 rootkits 隱藏的連線狀態
如果 Suggested profile 是 WinXP 可以用 connscan ,其他用 netscan
有幾點我們可以注意的 :

  1. 其是否對外提供服務
  2. 是否在 DMZ
  3. Service port 是否正常
  4. 檢查其是否在黑名單中
  5. Service port 是否正常( PID 碼是往下追查的唯一 key )
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] connscan

image

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] netscan

image

列出已連結或離線之程序(包含停止活動和rootkits隱藏的程序)

可以根據異常的 PID 往下追查
TimeStamp 很重要,是 Report 的必要元素

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] psscan

image

列出在特定檢視程序指令下會隱藏的程序

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] psxview

True : 指令、參數底下都會show出的結果,不用優先看
False : 特定指令看不到,可以先觀察差異欄位,進行反鑑識
像是此例子要先針對 cmd.exe 進行進一步追查,雖然他是 cmd.exe 但也有可能是惡意程式偽裝

image

列出正在執行的程序(找不到停止活動和rootkits隱藏的程序)

pstree 會列出樹狀結構

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] pstree
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] pslist

找出系統註冊碼

SAM = 帳號對應的 LM/NTLM hash
system = SYSKEY(用來再加密 SAM)
只要 Heartbleed 漏洞沒修補,攻擊者就能一直讀取記憶體內容,所以只把密碼改強也沒用。

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] hivelist

image

查看 password 的 hash

查看 Windows 的 NTLM hash,可以進一步用 John the Ripper 破解出 Password

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] hashdump -y [key 的 offset] -s [hash 的 offset]

image

列出曾經下過的 Windows cmd 指令

cmd 不會列出 Timstamp,只會有執行順序

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] cmdscan

image

將 hiberfil.sys 轉成 .dd 映像檔

hiberfil.sys : Windows 休眠時儲存的壓縮、重映後的 RAM 檔案
若要分析 hiberfil.sys ,需要先解壓縮和排序,變成 .dd 映像檔

volatility_2.6_win64_standalone.exe volatility -f hiberfil.sys imagecopy -O [檔案名稱.dd]

image

找出執行程序目前所開啟的 handles 資源

下圖為找出與 1524 port 相關之目前所開啟的handles資源
如果看見 $Recycle.Bin 或 SID/RID 要特別注意,通常代表刪除後仍然被佔用的檔案,或是帳號被挾持。

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] handles -p [port]

image

其他功能

  • yarascan : 透過YARA規則進行正規化規則比對
  • malfind : 找出被隱藏或插入程式/DLL
  • poisonivyconfig : 解析惡意程式設定檔
  • procexedump : 匯出程式
  • filescan : 找出目前正被開啟的檔案物件

上一篇
[DAY 08] 副檔名會騙人,Hex 不會
下一篇
[DAY 10] Volatility 2.6 分析案例
系列文
那些留在電腦裡的證據:從零開始認識數位鑑識 共 18 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言