Skip to content

ueFAUrensics/UEberForensIcs

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 

Repository files navigation

UEberForensIcs

With UEberForensics we integrate forensic software that enables cold boot like memory acquisition directly into a computer's firmware. The proof-of-concept is implemented as a DXE-Driver for OVMF based on EDK II. The driver acquires the memory and sends it via TCP to a forensic workstation server.

Implementation

UEberForensic is implemented as a standalone application and also as a dynamic command. It does not store memory dumps on the local drive as it would lead to corruption, but exfiltrates the data via the network. This is achieved via the EDK II TCP stack.

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published