Airwatch MDM and Android: a policy and technical review
A component of memory forensics is the examination of running processes looking for anomalies. However, this assumes that the analyst can recognize the anomalies. A frame of reference to assist the analyst is the creation of a baseline which identifies what is expected to be present in memory for a given configuration.
35372 (PDF, 2.76MB)
21 Aug 2014ByTimothy Collyer
