1. Using Encase create the following GREP Expression:
\x00\x14\x00\x00\x01\x02..\x03
2. Run against the DFRWS Dump and review your findings:
The information contained in the BIOS is pretty substantial often including make, model and serial number of the computer the data was collected
So far the BIOS Magic Numbers have found the BIOS Information on every RAM Acquisition I have tested it on. (Win2000 to Vista).
Future Work:
1. Find the Length of the BIOS Information or a Good Footer.
2. Place in RAM Enscript
No comments:
Post a Comment