Jun 13, 2022 03:12
2 yrs ago
10 viewers *
English term
image to
English to Chinese
Tech/Engineering
IT (Information Technology)
malware analysis
Malware Analysis Tutorials – Memory Forensics
Memory volatile artifacts found in physical memory. Volatile memory Forensics contains valuable information about the runtime state of the system, provides the ability to link artifacts from the traditional forensic analysis (network, file system, registry).
mage the full range of system memory (no reliance on API calls).
[Image] a process’ entire address space [to] disk, including a process’ loaded DLLs, EXEs, heaps, and stacks.
将进程的整个地址空间映像到磁盘?
Memory volatile artifacts found in physical memory. Volatile memory Forensics contains valuable information about the runtime state of the system, provides the ability to link artifacts from the traditional forensic analysis (network, file system, registry).
mage the full range of system memory (no reliance on API calls).
[Image] a process’ entire address space [to] disk, including a process’ loaded DLLs, EXEs, heaps, and stacks.
将进程的整个地址空间映像到磁盘?
Proposed translations
(Chinese)
4 | 保存(内存)镜像/映像 | Frank Feng |
4 | 抄录 | Kiet Bach |
Proposed translations
1 hr
Selected
保存(内存)镜像/映像
看上下文的描述,就是要把整个实时内存保存到硬盘上,作为证据(供分析)
相当于给内存“拍照片”
相当于给内存“拍照片”
4 KudoZ points awarded for this answer.
Comment: "谢谢!"
2 hrs
抄录
image ... to disk
把 ... 抄录到硬盘里
--------------------------------------------------
Note added at 4 days (2022-06-17 20:16:26 GMT)
--------------------------------------------------
为什么作者不用 copy (Copy a process’ entire address space to disk) 呢? 是因为这个 image(动词) 是要把 address space 的 (每一个 byte 的) 位置都要录下。
把 ... 抄录到硬盘里
--------------------------------------------------
Note added at 4 days (2022-06-17 20:16:26 GMT)
--------------------------------------------------
为什么作者不用 copy (Copy a process’ entire address space to disk) 呢? 是因为这个 image(动词) 是要把 address space 的 (每一个 byte 的) 位置都要录下。
Discussion