Part I
– Common usage
• As a listener : nc –l –p 8888 > image.dd
• This tells netcat to listen on port 8888 and anything
coming across will be written in to image.dd file.
• As a writer : ./memdump | ./nc 192.168.1.10 8888
• This send the output of memdump to netcat which
attaches to a remote listener on port 8888 at
192.168.1.10
Memdump - Windows
• System Information
• Uptime
• Uname
• Date/Time
• Process List
• Handle
• ListDlls
• Logon Sessions
• Services
• Netstat
System Information
Uptime - Windows
• Strings
• Mounting image in Linux
• Mounting image with FTK
• Extracting a file with FTK
• Internet Explore History - Pasco
Strings