Daily Blog #754: Pagefile carving with Page Brute
page_brute是一款开源数字取证工具,专注于从系统页面文件中解析逻辑数据块。它通过将页面文件分割为单个内存页大小的段,并应用YARA规则进行分类,能够有效恢复AJAX片段和其他临时网络对象,特别适合处理Web邮件调查中的小规模数据内容。 2025-2-20 03:34:0 Author: www.hecfblog.com(查看原文) 阅读量:6 收藏

By February 19, 2025

Hello Reader,

I’m often surprised by how many effective open source DFIR tools are overlooked. One of my favorites is page_brute. This tool tackles a tricky problem: parsing logical data chunks from the page file without accidentally merging memory segments from different programs.

Page_brute accomplishes this elegantly by carving the page file into segments equal to a single memory page. It then applies YARA rules to categorize each chunk. I mainly use it to recover AJAX fragments and other temporary web objects that never make it to disk. Since the content I’m after is usually small enough to fit within one memory page, this approach works exceptionally well for webmail investigations.

If you’re looking for a reliable method to recover and categorize page file contents, I highly recommend giving page_brute a try: GitHub - matonis/page_brute.


文章来源: https://www.hecfblog.com/2025/02/daily-blog-754-pagefile-carving-with.html
如有侵权请联系:admin#unsafe.sh