Metasploit Autopsy: Recontructing the Crime Scene

DEF CON 17

Presented by: Iftach Ian Amit (@iiamit), Joseph McCray
Date: Saturday August 01, 2009
Time: 18:50 - 19:20
Location: Track 2
Track: Track 2

Meterpreter is becoming the new frontier of malicious payloads, allowing an attacker to upload files that never touch disk, circumventing traditional forensic techniques. The stealth of meterpreter creates problems for incident responders. Such as how does a responder determine what occurred on a box exploited by meterpreter?

During this talk we discuss accessing physical memory for the purpose of acquiring a specific processes’ address space. Process address space acquisition includes DLLs, EXEs, stacks and heaps. This includes memory resident modules. We describe in detail how meterpeter operates in memory and specifically how memory looks when meterpreter scripts/commands are executed and the residue these scripts create in the exploited processes’ memory space. Finally, we tie all this knowledge together and discuss how to reconstruct a meterpreter session – completely from memory – and determine what the attacker was doing on the exploited machine.

The talk will conclude with the demonstration of a new tool, the audience will see how an attacker using meterpreter is no longer hidden from the forensic investigator, as we recreate the meterpreter session from memory.

Peter Silberman

<strong>Peter Silberman</strong> works at MANDIANT on the product development team. For a number of years, Peter has specialized in offensive and defensive kernel technologies, reverse engineering, and vulnerability discovery. He enjoys automating solutions to problems both in the domain of reverse engineering and rootkit analysis. Although he is college educated, Peter does not believe formal education should interfere with learning.

Steve Davis

<strong>Steve Davis</strong> is a Consultant in Mandiant’s Alexandria, Virginia office. Mr. Davis specializes in exploit research and development, malware analysis, and application and network vulnerability assessments. He has developed numerous internal tools to aid in penetration tests and malware analysis. Mr. Davis has also instructed malware analysis and wireless security courses at industry standard conferences, to include Black Hat, and to private clientele.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats