共 4 条
[1]
Intel? 64 and IA-32 Architectures Software Developer‘s Manual Volume 3A. http://www.intel.com .
[2]
Searching for processes and threads in microsoft Windows memory dumps[C/OL]. Schuster A. Proceedings of the2006Digital Forensic Research Workshop(DFRWS) . 2006
[3]
Digital forensics of the physical memory. Burdach M. http://forensic.seccure.net/pdf/mburdach_digital_forensics_of_physical_memory.pdf . 2005
[4]
An introduction to Windows memory forensic. Burdach M. http://forensic.seccure.net/pdf/introduction_to_windows_memory_forensic.pdf . 2005