Artifact, Malware, and Ransomware Analysis
In this chapter, we’ll cover several different tools to uncover various digital artifacts, malware, and ransomware, some of which reside in RAM and the swap file, which, as we learned in the previous chapter, can be quite useful in our DFIR investigations.
To start things off, we will look into artifact analysis using tools such as p0f to identify devices and operating systems, use swap_digger for swap file analysis, and then use MimiPenguin for password dumping. Following this, we will dive into malware analysis using pdf-parser and PDFiD for PDF malware analysis, use Hybrid Analysis for malicious file analysis, and then end things off by using Volatility 3 for ransomware analysis.
The following topics will be covered in this chapter:
- Identifying devices and operating systems with p0f
- Looking at the swap_digger tool to explore Linux artifacts
- Password dumping with MimiPenguin
- PDF malware analysis
- Using...