Show simple item record

dc.contributor.authorLeopard, Charles B.
dc.contributor.authorRowe, Neil C.
dc.contributor.authorMcCarrin, Michael R.
dc.date3/31/2018
dc.date.accessioned2019-02-01T20:25:35Z
dc.date.available2019-02-01T20:25:35Z
dc.date.issued2018-03-31
dc.identifier.citationLeopard, Charles B., Neil C. Rowe, and Michael R. McCarrin. "TESTING MEMORY FORENSICS TOOLS FOR THE MACINTOSH OS X OPERATING SYSTEM." The Journal of Digital Forensics, Security and Law: JDFSL 13.1 (2018): 31-42.en_US
dc.identifier.urihttps://hdl.handle.net/10945/61135
dc.descriptionA shortened version of this paper appeared in the Proceedings of the Ninth EAI International Conference on Digital Forensics and Computer Crime, Prague, Czech Republic, October 2017.
dc.descriptionThe article of record as published may be found at http://dx.doi.org/10.15394/jdfsl.2018.1491en_US
dc.description.abstractMemory acquisition is essential to defeat anti-forensic operating-system features and investigate cyberattacks that leave little or no evidence in secondary storage. The forensic community has developed tools to acquire physical memory from Apple's Macintosh computers, but they have not much been tested. This work tested three major OS X memory-acquisition tools. Although the tools could capture system memory accurately, the open-source tool OSXPmem appeared advantageous in size, reliability, and support for memory configurations and versions of the OS X operating system.en_US
dc.format.extent12 p.en_US
dc.publisherEmbry-Riddle Aeronautical Universityen_US
dc.rightsThis publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.en_US
dc.titleTesting Memory Forensics Tools for the Macintosh OS X Operating Systemen_US
dc.typeArticleen_US
dc.contributor.corporateNaval Postgraduate School (U.S.)en_US
dc.contributor.departmentComputer Science (CS)
dc.subject.authordigital forensicsen_US
dc.subject.authoracquisitionen_US
dc.subject.authormain memoryen_US
dc.subject.authorMacintoshen_US
dc.subject.authorOSXen_US
dc.subject.authortestingen_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record