To demonstrate some of the key features of Redline, the Stuxnet memory capture will be used. To conduct an analysis, follow these steps:
- Install Redline via the Microsoft Self Installer.
- Once installed, double-click on the icon and the following screen will appear. There are a number of options broken down into two categories: Collect Data and Analyze Data. In this case, the Stuxnet memory capture will be analyzed:
- Click on From a Saved Memory File in the Analyze Data category. This will open a second window. Under Location of Saved Memory Image, navigate to the location of the memory file and select it. Click ...