Note:
This awardee has received supplemental funding. This award detail page includes information about both the original award and supplemental awards.
Award Information
Description of original award (Fiscal Year 2009, $321,276)
This project will develop Mem Marshal, a toolkit for volatile memory analysis that will assist law enforcement investigators by automating memory analysis capabilities. Mem Marshal will be a user-friendly, automated memory analysis system that can be used by digital forensic investigators to examine and visualize data in captured memory. Memory analysis will produce important, case-relevant data for investigators that cannot be obtained from disk analysis: running applications, open files, Web browser usage, recently-used passwords, and stored encryption keys. Using Mem Marshal's memory analysis will enable investigators to focus and enhance time-consuming disk analysis, thus reducing investigation time by using information acquired from memory images, which can be searched and analyzed quickly. ca/ncf