Chapter 8: Artifact Analysis
In this chapter, we'll cover several different tools to uncover various artifacts that may be very useful to our forensic investigations. Most of the tools used in this chapter focus specifically on memory and swap analysis, while Network Mapper (Nmap) and p0f focus more on the network and device.
In this chapter, we'll cover the following topics:
- Identifying and fingerprinting devices, operating systems, and running services with p0f and Nmap
- Analyzing memory dumps to discover traces of ransomware
- Performing swap analysis
- Using
swap_digger
andmimipenguin
for password dumping - Examining the Firefox browser and Gmail artifacts using
pdgmail