请输入您要查询的百科知识:

 

词条 WindowsSCOPE
释义

  1. Acquisition

  2. Analysis

  3. References

  4. External links

{{Infobox software
| name = WindowsSCOPE
| developer = WindowsSCOPE
| platform = Windows, Cloud
| language = English
| status = Active
| genre = Computer forensics, Reverse Engineering
| website = http://www.windowsscope.com
}}

WindowsSCOPE is a memory forensics and reverse engineering product for Windows used for acquiring and analyzing volatile memory. One of its uses is in the detection and reverse engineering of rootkits and other malware.[2] WindowsSCOPE supports acquisition and analysis of Windows computers running Windows XP through Windows 10.

Acquisition

WindowsSCOPE supports both software-based acquisition as well as hardware-assisted methods for both locked and unlocked computers. WindowsSCOPE add-on hardware for memory acquisition uses the PCI Express bus for direct access to system memory. Memory snapshots acquired with WindowsSCOPE are stored in a repository. Memory snapshots in the repository can be compared to track changes in the system over time.[2]

Analysis

WindowsSCOPE shows processes, DLLs, and drivers running the computer at the time of the memory snapshot as well as open network sockets, file handles, and registry key handles. It also provides disassembly and control flow graphing for executable code. WindowsSCOPE Live is a version of the tool that allows analysis to be performed from a mobile device.[4]

References

1. ^{{cite web|last=Le Masle|first=Adrien|title=Detecting the HackerDefender rootkit using WindowsSCOPE|publisher=Imperial College London|url=http://www.doc.ic.ac.uk/~al1108/website/doku.php?id=windowsscope|accessdate=10 April 2012}}
2. ^{{cite web|last=Storm|first=Darlene|title=Encrypt: Be anti-forensic friendly to protect your Android and your privacy|url=http://blogs.computerworld.com/19469/encrypt_be_anti_forensic_friendly_to_protect_your_android_and_your_privacy|work=Security Is Sexy|publisher=Computerworld|accessdate=10 April 2012}}
[1][2]
}}

External links

  • WindowsSCOPE Web Site

2 : Computer forensics|Digital forensics software

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/11/11 18:59:03