This class was created by Brainscape user Alex Moorman. Visit their profile to learn more about the creator.

Decks in this class (17)

Memory Architecture
Computer buses,
Memory management unit mmu,
Translation lookaside buffer tlu
34  cards
Windows Executable Objects
_file_object,
_eprocess,
_object_symbolic_link
11  cards
Object Headers
Pointercount,
Handlecount,
Typeindex
11  cards
Pools
Kernel pool,
Pooltype,
Obcreateobject
9  cards
_EPROCESS Contents
Pcb,
Createtime,
Exittime
13  cards
Critical System Processes
Idle,
System,
Csrssexe
9  cards
Volatility Commands Related to Processes
Pslist,
Pstree,
Scans for _eprocess objects inste...
4  cards
Alternate Process Listings
Process object scanning,
Thread scanning,
Csrss handle table
6  cards
Analyzing Privileges
Sebackupprivilege,
Sedebugprivilege,
Seloaddriverprivilege
15  cards
Address Space Layout
Dynamic linked libraries dlls,
Environmental variables,
Process environment block peb
7  cards
Enumerating Process Memory Tools
Virtual address descriptors vads,
Working set list,
Pfn database
6  cards
Permissions
Page_execute,
Page_execute_read,
Page_execute_readwrite
9  cards
Key Points for _PEB
_peb beingdebugged,
_peb imagebaseaddress,
_peb ldr
9  cards
Key Points for _RTL_PROCESS_PARAMETERS:
_rtl_process_parameters standardi...,
_rtl_process_parameters standardo...,
_rtl_process_parameters standarde...
7  cards
_PEB_LDR_DATA and _LDR_DATA_TABLE_ENTRY
_peb_ldr_data,
_peb_ldr_data inloadordermodulelist,
_peb_ldr_data inmemoryordermodule...
10  cards
Standard Handles & Suspicious DLLs
Ws2_32dll,
Crypt32dll,
Hnetcfgdll
13  cards
Volatility Plugins
Pslist,
Pstree,
Psscan
4  cards

More about
Forensics

  • Class purpose General learning

Learn faster with Brainscape on your web, iPhone, or Android device. Study Alex Moorman's Forensics flashcards for their UTSA class now!

How studying works.

Brainscape's adaptive web mobile flashcards system will drill you on your weaknesses, using a pattern guaranteed to help you learn more in less time.

Add your own flashcards.

Either request "Edit" access from the author, or make a copy of the class to edit as your own. And you can always create a totally new class of your own too!

What's Brainscape anyway?

Brainscape is a digital flashcards platform where you can find, create, share, and study any subject on the planet.

We use an adaptive study algorithm that is proven to help you learn faster and remember longer....

Looking for something else?

Forensic Anatomy
  • 46 decks
  • 1062 flashcards
  • 2 learners
Decks: Introduction, Head And Neck General Terms, Nervous System Terms, And more!
French
  • 121 decks
  • 6695 flashcards
  • 1289 learners
Decks: Expressions 3, Vocab 68, Vocab 66, And more!
Forensics
  • 32 decks
  • 424 flashcards
  • 1 learners
Decks: Lecture 1 Changes After Death, Lecture 2 Dna And Its Applications, Work Of Forensic Pathologists, And more!
Make Flashcards