Redline analysis process

To demonstrate some of the key features of Redline, the Stuxnet memory capture will be used. To conduct an analysis, follow these steps:

  1. Install Redline via the Microsoft Self Installer.
  1. Once installed, double-click on the icon and the following screen will appear. There are a number of options broken down into two categories: Collect Data and Analyze Data. In this case, the Stuxnet memory capture will be analyzed:
  1. Click on From a Saved Memory File in the Analyze Data category. This will open a second window. Under Location of Saved Memory Image, navigate to the location of the memory file and select it. Click ...

Get Digital Forensics and Incident Response - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.