top of page

ืื™ืš ื—ื•ืงืจื™ื RAM

ืขื•ื“ื›ืŸ: 31 ื‘ื™ื•ืœื™ 2020

1.ืฆืจื™ืš ืœื”ื•ืจื™ื“ FTK IMAGER

2.ื‘ืฉื‘ื™ืœ ืœื“ืขืช ืื™ืš ืชื•ืคืกื™ื RAM ืœื—ืฅ ื›ืืŸ

3.ืฆืจื™ืš ืœื”ื•ืจื™ื“ ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืฉื ืงืจืช CAINE ืœื—ืฅ ื›ืืŸ ืœืงื™ืฉื•ืจ

4.ืœื”ืขื‘ื™ืจ ืืช memdump.mem ืœCAINE ื›ื“ื™ ืœื“ืขืช ืื™ืš ืœื”ืขื‘ื™ืจ ืงื‘ืฆื™ื ื‘ืืžืฆืขื•ืช NC ืœื—ืฅ ื›ืืŸ ืื• ื‘ืขืžืฆืื•ืช WINSCP ืœื—ืฅ ื›ืืŸ



ื›ื“ื™ ืœื‘ื“ื•ืง ืฉืขื•ื‘ื“ ctrl+ shift+t ื• ls -la ื›ืžื” ืคืขืžื™ื ื›ื“ื™ ืœืจืื•ืช ืื ื”ืงื•ื‘ืฅ ื’ื•ื“ืœ












5.ืœื•ื—ืฆื™ื ืขืœ ื”ืงื™ืฉื•ืจ ื›ืืŸ ืขื•ืฉื™ื ื”ืขืชืง ื”ื“ื‘ืง ืฉืœ ื”SCRIPT ื•ืกืžื™ื ืื•ืชื• ื‘ืชื•ืš DOCUMENT TEXT ื•SAVE ื•ื ื•ืชื ื™ื ืฉื DEFENCE

6.ืขื•ืฉื™ื ื‘ืชื•ืš ื”ืžื›ื•ื ื” ืœื™ื ื•ืงืก mkdir memoryforensics

6.ืžืขื‘ื™ืจื™ื ืืช ื”ืงื•ื‘ืฅ defence.txt ืœืžื›ื•ื ื” ืœื™ื ื•ืงืก ื‘ืชื•ื— ื”ืชื™ืงื™ื™ื” ืฉื™ืฆืจืชื memoryforensics

7.ื•ืžืขื‘ื™ืจื™ื ื’ื ืืช memdump.mem ืœืชื•ืš ื”ืชื™ืงื™ื™ื”

8.ืžื•ืจื™ื“ื™ื ืืช vol.py ื›ืืŸ ืงื™ืฉื•ืจ

9.ืžื•ืจื™ื“ื™ื ืืช TEKDEFENDER ื›ืืŸ ืงื™ืฉื•ืจ ื•ืžืขื‘ื™ืจื™ื ืื•ืชื• ืœืชื™ืงื™ื™ื” (ืฆืจื™ืš ืœืขืฉื•ืช UNZIP )

10. ืœื•ืงื—ื™ื ืืช vol.py ื‘ืชื•ืš ื”ืชื™ืงื™ื™ื” ืฉืœื ื•

11.chmod 777 vol.py

12.ืฆืจื™ืš ืœื”ื—ืœื™ืฃ ืืช ื”ืฉื ืฉืœ defence.txt ืœ defense.sh

mv defence.txt defence.sh


13.chmod 777 defence.sh

14. ื•ืœื”ืจื™ืฅ ืืช defence.sh










15. ืœืฉืžื•ืข ืœื”ื•ืจืื•ืช

ืฉื ืจื MEMDUMP.MEM

ืœืชืช ืฉื ืžืœื ืฉืœ ืžืขืจื›ืช ื”ืคืขืœื”

16.ื™ื•ืชืจ ืฉื”ืงื•ื‘ืฅ MEMDUMP.MEM ื›ื‘ื“ ื•ื™ื•ืชืจ ื™ืงื— ื–ืžืŸ ืื– ืœื ืœื“ืขื•ื’

17.ื™ืฉ ืœื›ื ืืช ื›ืœ ื”ืงื‘ืฆื™ื ืฉืœื›ื ื‘ืชื•ืš ื”ืชื™ืงื™ื”


18 ื‘ืฉื‘ื™ืœ ืœื“ืขืช ืžื” ื›ืœ ืงื•ื‘ืฅ ื ืชืŸ ื•ืžื” ื”ืชื•ื›ืŸ ืฉืœ ื›ืœ ืงื•ื‘ืฅ ืœื—ืฅ ื›ืืŸ

ืœื™ืฆื™ืจืช ืงืฉืจ ื•ืฉื™ืจื•ืช ื˜ื›ื ืื™ ืžื—ืฉื‘ื™ื ื‘ื™ืจื•ืฉืœื™ื ืขื“ ื”ื‘ื™ืช ื—ื™ื™ื’ื• โ€“ 0532104457

28 ืฆืคื™ื•ืช0 ืชื’ื•ื‘ื•ืช

ืคื•ืกื˜ื™ื ืื—ืจื•ื ื™ื

ื”ืฆื’ ื”ื›ื•ืœ
bottom of page