Physical Disk+RAM Dump
Posted: 29. Aug 2011, 12:57
Hello!
I have been trying to search for a solution to get a physical RAM Dump of a VM using VirtualBox but there is no way apparently ...
On VMWare we have the .vmem files for the physical RAM ... but for VirtualBox ...
There are .sav file when suspending the VM but I have not found documentation on this file format in order to be able to write a program to extract the physical RAM from it.
Would be great to have firewire or thunderbolt emulation to allow for memory dump through DMA capability.
Would also be great to be able to insert any other keys combination in order to be able to force a bug check on Windows using the CtrlScrollLock trick. (Not all keyboards have a conveniently accessible Scroll Lock key such as my Logitech Keyboard ...).
The advantages of being able to get a hold of a VM physical RAM is that we can do forensic+security+other specific research on it without having DMA remapping attacks for example (and thus falsified RAM dump).
For the disk part, I managed to obtain a RAW image of a virtualbox hard disk image using this command:
Cheers,
Thank you in advance for your answers,
kurapix
I have been trying to search for a solution to get a physical RAM Dump of a VM using VirtualBox but there is no way apparently ...
On VMWare we have the .vmem files for the physical RAM ... but for VirtualBox ...
There are .sav file when suspending the VM but I have not found documentation on this file format in order to be able to write a program to extract the physical RAM from it.
Would be great to have firewire or thunderbolt emulation to allow for memory dump through DMA capability.
Would also be great to be able to insert any other keys combination in order to be able to force a bug check on Windows using the CtrlScrollLock trick. (Not all keyboards have a conveniently accessible Scroll Lock key such as my Logitech Keyboard ...).
The advantages of being able to get a hold of a VM physical RAM is that we can do forensic+security+other specific research on it without having DMA remapping attacks for example (and thus falsified RAM dump).
For the disk part, I managed to obtain a RAW image of a virtualbox hard disk image using this command:
Code: Select all
VBoxManage internalcommands converthd -srcformat FORMAT1 -dstformat FORMAT2 SRCFILE DSTFILEThank you in advance for your answers,
kurapix