Monday, November 14, 2016

Bringing together the DFIR Industry and Academia at DFRWS 2017

I am happy to announce that I have joined the 2017 DFRWS organizing committee. My role for this conference is to bring industry researchers and practitioners into the fold in order to help bridge the gap between the Digital Forensics & Incident Response (DFIR) industry and the academic digital forensics community.   I find this task to be highly important as there are a number of areas where industry and academia could better collaborate (or collaborate at all), and where the skills and strengths of each could greatly benefit the other.  With this post I hope to explain why I think DFRWS is the best venue for this collaboration to occur, discuss the many potential benefits, and to inspire a few of my industry friends and colleagues to participate.

Comparing Academic Research to Industry Research


In the digital forensics & incident response industry, the usual means of research dissemination is through conference presentations. These presentations are usually 45 to 60 minutes in length, and the only documentation produced is PowerPoint files – many of which are not made available after the conference. This method of knowledge and research effort distribution makes it difficult for those who do not attend the talk to gain full value from it. To remedy this issue, a handful of conferences now record the video of speakers and post them online after the event.

While this is certainly more useful for those who do not attend the talk live, it still leaves much to be desired. In particular, many research presentations simply highlight the results of the effort and how they can be transitioned to the field. There is generally no discussion of the process that the presenter went through to perform their research, the statistical significance of the results, or the data set used to test the validity of the results. This makes the effort non-repeatable by other researchers and weakens the effect of the research. Industry research is also usually focused on particular versions of malware or operating systems instead of a more general approach that can be widely applied outside the presenter’s test environment.

Paper Submissions

This approach is in great contrast to academic conferences. When submitting to academic conferences, the first material submitted is an 8-12 page paper that undergoes peer review.  This paper describes in full detail the research approach taken, how it improves upon previous efforts, where the effort fell short, the environment used to test the research, and the improvements still needed to make it applicable to use in the field, if any. Only after a paper is accepted for publication is an associated presentation developed.

The requirement of a paper submission generally leads to higher quality research as the research project must be completed or nearly completed before being submitted. This means that there is little room for “hand waving” by the author during the submission process and that only verified results are discussed. With the notable exceptions of Black Hat and DefCon, industry conferences do not enforce the inclusion of a paper with all research submissions, and as a result, many subpar presentations are accepted.

Double-Blind Peer Review

Along with the paper submission requirement, academic conferences also have the advantage of the review process being "blind”. To quote the Elsevier review guidelines document, double blind “means that both the reviewer and author identities are concealed from the reviewers, and vice versa, throughout the review process”. This again raises the quality of accepted papers as people are not accepted based on name or company recognition, which is an issue that plagues some industry conferences, but instead on technical merit.

Furthermore, the blind review process allows for honest and direct feedback, which is often muted or not possible if the reviewer is a colleague of the author(s) or if the authors know all of the reviewers. To work around this issue, academic conferences combine the blind review process along with much larger review teams than typically used for industry events. To ensure that reviewers are not assigned papers to review from their colleagues or friends, each conference generally has one or two people who assign all of the review tasks while keeping potential conflicts in mind.

Detailed Submission Feedback

Since reviewers are free from potential conflicts of interest when reviewing, this allows for detailed feedback, both positive and negative, to submissions. As someone who has had papers rejected from academic conferences, I can assure you that reviewers do not hold back with their criticism or praise. For the conferences that I have submitted to, it seems normal to receive detailed feedback from 4 to 8 reviewers along with their selected review score.  Authors of accepted papers are expected to incorporate the feedback from reviews into the final versions of their paper. This process again raises the quality of published papers.

The reception of detailed feedback is in contrast to most industry conferences that simply send a standard email informing the submitter that their work was either accepted or rejected. The lack of feedback to accepted submitters provides no direction on improvements that can be made, and the lack of feedback to rejected submitters can be highly frustrating.

Benefits of Industry Collaboration with Academia


Beyond providing a venue for thorough and peer-reviewed research to be published, academic conferences also provide a number of immediate benefits to industry organizations and individuals who take advantage of them.

Building Employee Candidate Pipelines

By attending and participating in academic security conferences, a company and its employees gain immediate visibility throughout the academic community. This allows for building relationships with professors who teach forensics and security inside of programs, such as Computer Science, as well as networking opportunities with students who are engaged enough to attend conferences. These types of students generally make great future hires, and everyone in the industry is painfully aware of how hard hiring in information security is. By building relationships with professors, companies can also make hiring much easier as professors are eager to see their students become employed in a meaningful job after graduation.  Besides careers for graduated students, this pipeline can also be a feeder for robust internship programs.

For my many industry friends who are adjunct professors at universities, publishing at academic conferences with your students is a great way to push them beyond what the class minimally requires and is also a great way to find future hires.

Collaboration with Students and Research Labs

Unlike industry conferences, where most research is performed and presented by a single person, academic research is often conducted in groups of 2 to 5 people.  This allows for industry researchers to embed themselves within existing university research teams in order to perform large research projects and achieve results otherwise not attainable. Such partnerships can lead to business ventures between academia and industry, as well as further develop relationships with professors and students.

Influencing Curriculum Development

A constant complaint from members of the DFIR industry is that students in Computer Science and other related programs are not being offered digital forensics and computer security courses that match real-world needs. By networking with professors and students, industry practitioners can begin to influence curriculum development by showing the industry’s needs.

Why DFRWS?


Even when considering other top-tier academic conferences, such as USENIX Security, ACSAC, and IEEE S&P, I still believe that DFRWS is the best conference for collaboration between industry and academia. I hold this belief for a few reasons:

1) DFRWS has been the venue for the release of practical and highly impactful research in the malware, memory, disk, and network forensics spaces. This can be seen in Brendan Dolan-Gavitt’s work related to VADs and the registry in memory, Andreas Schuster’s work related to pool scanning and event logs, file carving, registry forensics, and memory acquisition. If you have ever used Scalpel, Volatility, Bulk Extractor, and/or the Sleuthkit then you are using tools built in part from research originally presented at DFRWS.

2) The yearly DFRWS challenges have led to ground-breaking research in memory and network forensics.

3) DFRWS already strives to mix purely academic research with research that is applicable in the field. This leads to papers with the benefits of academic research as described earlier as well immediate application to our daily jobs in the field. The existing efforts of DFRWS to bring together academic and industry researchers has already yielded significant results over the last 10+ years and I hope to expand that collaboration in my new role with the conference.

4) Student scholarships! DFRWS also provides conference scholarships for select students who present original research. The details are spelled out on the website, but this can be a nice way for students without a travel budget to offset costs.

More Reasons to Submit!


Personal Branding and Career Potential

Beyond presenting at industry conferences, being able to list peer-reviewed, academic publications on your resume is a huge career boost. For positions, such as CISO, CTO, or Director of Research, many organizations require such publications. These publications can also go a long way in justifying the N years of experience that many positions require for those without a traditional four-year degree.  Also, if you ever decide to go back to school for a Masters or PhD, then you will need to demonstrate some level of research competence.

Great Location and a New Experience

If you have made it this far, and I still have failed to convince you that DFRWS is worth a chance, then what about the fact that it is in Austin this year? Even if all else fails and you hate the conference, then at least you are surrounded by great BBQ, music, and beer! DFRWS also rotates its location yearly, so by putting DFRWS on your annual calendar then you will get to visit many great cities along with learning about a bunch of cutting-edge topics in digital forensics.

Closing Thoughts


In closing, I hope that my industry colleagues will consider starting a research project and submitting the results to DFRWS. Also, don’t be intimated by the idea of submitting to an academic conference. The DFRWS archives has all of the conference’s previously accepted papers, which you can use as templates. Furthermore, for papers with strong technical merit, but that need some editing love, DFRWS provides a “shepherding” process where reviewers help you format and mold content to make your paper as well written as it can be.

If you have any questions about DFRWS, submitting, or how to shape your research ideas then please contact me.

I hope to see you in Austin next summer!




Friday, September 4, 2015

November is the month of DFIR books

I keep a wishlist of upcoming books and recently noticed that four high-quality technical books will be coming out in November. These cover a wide range of topics, and at least one should interest everyone in the DFIR world.

The first is a professional Go book written by the authors of the language:


Next is a much anticipated update to the Linux Device Drivers series. For those unaware, this is the Linux equivalent to Windows Internals:


Third is Harlan Carvey's latest book, the 2nd edition of Windows Registry Forensics:


And last but not least is David Thiel's book on iOS Application security:


I expect all of these books to be of high quality and well worth your time if you are interested in the particular subject matter. I am already planning to preorder all four of them!



Saturday, August 30, 2014

Recommending Reading - A new resource for those looking to learn

I am often asked about which books should be read related to topics in computer security and forensics. Sometimes these questions come from new people who want to break into the field while others come from experienced people wanting to branch out or to really deep dive into a specific subject. In the past, I have generally answered these questions in ad-hoc way, whether through a customized email or over instant messenger.

In an attempt to centralize my book recommendations, I have created a Recommend Reading page on my website. This page lists books across a range of categories (security, forensics, reversing, etc.), provides a brief insight into each book's contents, and also lists the general technical know-how of the specific topic needed to understand the book.

This page is a work in progress, and I definitely welcome suggestions for updates and new additions. Please note that I will only list books that I have actually read. With that said, I do accept review copies of books and often pick up new books that seem interesting.

I would like to thank Ashley and Vico for helping with the design of the page and for proof reading.

Thursday, August 14, 2014

Interview with Eric Huber on A Fistful of Dongles

I was recently interviewed by Eric Huber on his popular AFOD blog. I went into some details of my path to where I currently am in my digital forensics career and some advice for people new to the field.

http://www.ericjhuber.com/2014/08/afod-blog-interview-with-andrew-case.html

Wednesday, April 9, 2014

Building a Decoder for the CVE-2014-0502 Shellcode

Yesterday on the Volatility Labs blog I published a post on analyzing some interesting shellcode from a recent attack campaign and 0day exploit. The shellcode was encrypted multiple times and required full static reversing before revealing the algorithm needed to decrypt the backdoor URL. I think you will like it:

http://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html


Monday, November 25, 2013

Our Registry Forensics Master Class is now Live!



I am very happy to announce that the Registry Forensics Master Class that I developed in conjunction with 504ENSICS is now live. The master class is completely focused on registry forensics, and takes students from the basics through advanced topics and analysis techniques. A few of the topics covered include:


  • Acquiring hives from both disk images and memory samples
  • Understanding the raw artifacts contained in the variety of hives
  • Analyzing the artifacts using a number of popular forensics tools
  • Scripting registry forensics tools for automated and repeatable analysis
  • Timelining registry contents
  • Baselining hives to determine activities caused by malware and user actions
  • Incorporating Windows backup facilities into registry analysis
  • Investigating the registry in volatile memory (RAM)
  • Analyzing malware in the registry 
  •  Defeating anti-forensics


The class is an online, self-paced course that mimics what would be covered in a 2-3 day in-person offering. Each lesson in the course includes a lecture that teaches a specific topic in registry forensics followed by a hands-on exercise. The exercises are completed in online Windows and Linux virtual machines that are pre-configured with all the tools and materials needed. To ensure students are learning the material, each exercise includes questions that must be answered in the quiz module. This module tracks a student’s progress, and can produce reports of the student’s grades so that course can be justified to managers and directors. Each exercise also comes with a complete lab guide that walks the student through how to answer each question as the instructors would.

The course ends with a large investigation that requires combining skills learned throughout the class. After completing the course, students will be able to immediately use the techniques learned in real-world investigations involving digital forensics, incident response handling, and malware analysis.

Leading up to our public release we asked Ken Pryor (@kdpryor), a well-known digital forensics analyst, to review the course. Upon completion, he provided the following feedback:

“The Windows Registry Master Class is a great course for new and veteran analysts alike. I entered the course expecting to learn a little something, but came out of it feeling like I got so much more than I had bargained for. Each module of the course taught me something new. The excellent labs reinforced what I learned in the modules and gave me the ability to gain firsthand knowledge of the material. I strongly recommend this course for analysts of all skill levels, as I believe everyone can gain from it.”

For more information on the course or to register, please see the Hacker Academy page where it is hosted here. If you have any questions about the course use the comment section below or email me at andrew [at] memoryanalysis.net. While the course is primarily offered online, we also have the ability to give the course to in-person groups.  If you have a group that is interested in these private offerings then please contact us as well.

Thanks,
Andrew (@attrc)

Tuesday, July 16, 2013

Results of the 4cast Awards Nominations

As previously announced, I was nominated for 'Digital Forensics Examiner of the Year' at the Forensics 4cast Awards. The awards ceremony was held last week during the DFIR summit, and I voted the winner in the category. I am very grateful for this award and recognition and hope to have another strong showing next year!

Monday, July 8, 2013

Interview on the Healthy Paranoia podcast

I was recently interviewed on the Healthy Paranoia podcast about memory forensics during DFIR as well as other related topics. It was a really fun time, and I hope to be on the show again in the future. Read about the interview and listen to the MP3 here:

http://packetpushers.net/healthy-paranoia-show-14-digital-forensics-and-incident-response-with-andrew-case/

Please contact me if you any feedback or comments about the show.

Thanks,
Andrew (@attrc)

Thursday, June 13, 2013

Final Week of Month of Volatility Plugins II is posted

We are writing as the final week of the second installment of the Month of Volatility Plugins is now posted. Volatility 2.3 is currently in beta, and the blog posts are focusing on new features in this version. 

This week's posts discussed a number of new and updated plugins used to analyze Mac systems. 

The first post demonstrated leveraging process cross-view analysis for Mac rootkit detection: 

http://volatility-labs.blogspot.com/2013/06/movp-ii-41-leveraging-process-cross.html 

The second post covered dumping, scanning, and searching process memory:

http://volatility-labs.blogspot.com/2013/06/movp-ii-42-dumping-scanning-and.html 

The third post discussed how to recover networking information:  

http://volatility-labs.blogspot.com/2013/06/movp-ii-43-recovering-mac-os-x-network.html 

The fourth post showed a number of artifacts in Mac kernel memory:  

http://volatility-labs.blogspot.com/2013/06/movp-ii-44-whats-in-your-mac-osx-kernel.html 

The fifth post analyzed the Rubilyn kernel rootkit and detected it in a number of ways:

http://volatility-labs.blogspot.com/2013/06/movp-ii-45-mac-volatility-vs-rubilyn.html 

We hope you have enjoyed this month's posts and will be trying 2.3 when its released!

Thanks,

Andrew (@attrc)

Wednesday, May 29, 2013

Second Week of Month of Volatility Plugins II is posted

We are writing as the second week of the second installment of the
Month of Volatility Plugins is now posted. Volatility 2.3 is currently
in beta, and the blog posts are focusing on new features in this
version. This week's posts discussed a number of new and updated
plugins used to analyze Windows systems.

The first post discussed recovering RSA Private Keys and SSL
Certificates from memory:

http://volatility-labs.blogspot.com/2013/05/movp-ii-21-rsa-private-keys-and.html

The second post discussed recovering information about unloaded kernel
modules from memory:

http://volatility-labs.blogspot.com/2013/05/movp-ii-22-unloaded-windows-kernel_22.html

The third post showed how to create timelines with in-memory data
using Volatility:

http://volatility-labs.blogspot.com/2013/05/movp-ii-23-creating-timelines-with.html

The fourth post demonstrated how to recover MFT entries and utilize
them during investigations:

http://volatility-labs.blogspot.com/2013/05/movp-ii-24-reconstructing-master-file.html

The last post highlighted a number of new and updated plugins that are
very useful during investigations:

http://volatility-labs.blogspot.com/2013/05/movp-ii-25-new-and-improved-windows.html

We hope you enjoy the posts, and the third week of posts will begin
tomorrow and cover a number of new plugins to help analyze Linux and
Android samples.

If you have any questions or comments please comment on an individual
blog post or reply to this email.

Thanks,
Andrew (@attrc)

First week of Month of Volatility Plugins II is posted

We are writing as the first week of the second installment of the
Month of Volatility Plugins is now posted. Volatility 2.3 is currently
in beta, and the blog posts are focusing on new features in this
version. This week's posts discussed a number of new address spaces we
have added to support new hardware architectures and file formats.

The first one is the MachO address space used to support Mac Memory Reader:

http://volatility-labs.blogspot.com/2013/05/movp-ii-11-mach-o-address-space.html

The second is an address space used to support VirtualBox:

http://volatility-labs.blogspot.com/2013/05/movp-ii-12-virtualbox-elf64-core-dumps.html

The third address space allows for analysis of VMware snapshot files
(.vmss and .vmsn):

http://volatility-labs.blogspot.com/2013/05/movp-ii-13-vmware-snapshot-and-saved.html

The fourth address space supports the hpak format of the HBGary Fast
Dump acquisition tool:

http://volatility-labs.blogspot.com/2013/05/movp-ii-14-new-hpak-address-space.html

The final address space discussed adds support for the ARM
architecture. This is leveraged by Volatility's Android support:

http://volatility-labs.blogspot.com/2013/05/movp-ii-15-arm-address-space-volatility.html

We hope you enjoy the posts, and the second installment of posts will
begin tomorrow and cover a number of new plugins to help analyzing
Windows samples.

If you have any questions or comments please comment on an individual
blog post or email the author.

Thanks,
Andrew (@attrc)

Tuesday, March 12, 2013

BSides New Orleans Speaker Lineup Published



We are writing to announce that the BSides New Orleans speaker lineup is now released. For those unaware, BSides New Orleans is a free, all day information security conference taking place on May 25th in New Orleans. We received so many strong submissions, from companies such as Google, Ernst & Young, Mad Security, and HP, that we have expanded the conference to 3 tracks for a total of 18 presentations. Complete information about the conference and speakers can be found here:


Between the strong lineup and the fact that the conference is New Orleans, we expect the seats to fill fast. If you want to attend (free), you must fill out the EventBrite form referenced on the wiki page. You only have to give your name and email for registration, and we promise not to spam you. If you have any questions about the event, please email bsidesnola [ @ ] gmail.com.

Thanks,
Andrew (@attrc)

Friday, February 15, 2013

Memory Forensics Talk at RSA!

On Wednesday of RSA I will be giving a talk titled:

"Memory Forensics: Defeating Disk Encryption, Skilled Attackers and Malware"

 This talk will focus on three key points:

1) Showcasing the power and usefulness of memory forensics
2) Distinguishing memory forensics from disk forensics
3) Highlighting why live forensics should not be used and instead analysts should switch to using offline memory forensics

Throughout the talk there will be many examples of powerful rootkits, techniques of advanced attackers, and looking at Android and software-based disk encryption.

If you are interested in the talk and plan on attending, please add it to your conference calendar:

https://ae.rsaconference.com/US13/connect/sessionDetail.ww?SESSION_ID=1885

If you have any questions about the talk or or want to meet up at RSA then please contact me or ping me on Twitter (@attrc).

Friday, January 25, 2013

BSides is coming to New Orleans!

I am happy to announce that we will be putting on a BSides in New Orleans on May 25. Full information can be found here:

http://www.securitybsides.com/w/page/62741761/BsidesNola

We already have Mike Murray confirmed as our keynote, and have had a few well-known researchers express interest in speaking. The CFP is open until March 11, so start thinking of topics!

Monday, January 14, 2013

Windows Malware and Memory Forensics Training in The Windy City!

The next journey to the center of Windows Memory Forensics starts in Chicago this March! 

We are pleased to announce the second public offering of the Windows Malware and Memory Forensics Training by The Volatility Project. This is the only memory forensics course officially designed, sponsored, and taught by the Volatility developers. One of the main reasons we made Volatility open-source is to encourage and facilitate a deeper understanding of how memory analysis works, where the evidence originates, and how to interpret the data collected by the framework's extensive set of plugins. Now you can learn about these benefits first hand from the developers of the most powerful, flexible, and innovative memory forensics tool. 

Appraisal from your peers who attended the first course this past December:



Please see the following details about the upcoming training event:

Dates: Monday, March 18th through Friday, March 22nd 2013
Location: Downtown Chicago, IL (exact location will be shared upon registration)
Instructors: Michael Ligh (@iMHLv2), Andrew Case (@attrc), Jamie Levy (@gleeda)

For more information about the course, view the Volatility Training Flyer (to download a copy of the PDF, click File > Download). To request a link to the online registration site or to receive a detailed course agenda/outline, please send an email voltraining [at] memoryanalysis.net.

The 1st Annual Volatility Framework Plugin Contest

We are pleased to announce the 1st Annual Volatility Plugin Contest. This contest is inspired and modeled after the Hex-Rays Plugin Contest.  As in the case of IDA, Volatility was designed with the belief that talented analysts should only be limited by their creativity not the tools they use. In this spirit, Volatility has a flexible architecture that can be extended in numerous ways: analysis plugins (operating system plugins, application plugins, etc), volshell commands, address spaces, profiles, or user interfaces. This contest is intended to inspire people to demonstrate their creativity, become a memory analysis pioneer, win the admiration of your peers, and give back to the community.

The contest is straightforward: Create an innovative and useful extension to The Volatility Framework and win the contest!

  • 1st place wins one free seat at any future Windows Malware and Memory Forensics Training *or* 1500 USD cash
  • 2nd place wins 500 USD cash
  • 3rd place wins 250 USD cash
  • 4th and 5th place wins Volatility swag (T-shirts, Stickers, etc)

Everyone but the Volatility core developers can participate.

Rules of Engagement

  1. The goal of the contest is to create innovative, interesting, and useful extensions for The Volatility Framework. While extensions written in Python are preferred, extensions written in other languages will also be considered.
  2. The submitted extensions should work with the Volatility 2.2 (or greater) release and should have been implemented after the initial contest announcement (1/14/2013).
  3. The top 5 winners of the contest will get the prizes mentioned above.
  4. Volatility core developers are not eligible.
  5. Submissions should be sent to volcon2013@memoryanalysis.net. The submission should include the source code, a short description of how the extension is used, and a signed "Individual Contributor License Agreement".
  6. By submitting an entry, you declare that you own the copyright to the source code and are authorized to submit it.
  7. All submissions should be received no later than August 1, 2013. The winner will be announced the following week. We recommend submitting early. In the case of similar submissions, preference will be shown to early submissions.
  8. The Volatility Project core developers will decide the winners based on the following criteria: creativity, usefulness, effort, completeness, submission date, and clarity of documentation.
  9. In order to collect the cash prizes, the winner will need to provide a legal picture identification and bank account information within 30 days of notification. The bank transfer will be made within two weeks after the winner is authenticated.
  10. Group entries are allowed; the prize will be paid (or seat will be registered, if the training option is desired) to the person designated by the group.
  11. Upon approval from the winners, their names/aliases will be listed on the "Volatility Hall of Fame" web page for the world to admire.
  12. Selected contestants may also be asked to present their work at the 2013 Open Memory Forensics Workshop or have their research featured on the Volatility Labs Blog.

Acknowledgements

A special thanks goes out to the Hex-Rays team for providing the inspiration and template for this contest.

Monday, December 10, 2012

Analyzing Malware in Memory Webinar

On December 18th I will be leading a webinar on analyzing malware in memory with Volatility and memory forensics techniques. The following link has a full abstract and registration info (its free):

http://www.thehackeracademy.com/tha-deep-dive-analyzing-malware-in-memory/


Monday, November 12, 2012

Android Forensics DFIROnline presentation

I was writing to say that I will be giving a DFIRonline presentation this Thursday on Android Forensics using Volatility and LiME:

http://www.writeblocked.org/index.php/dfironline.html

If you cannot make the live stream, be sure to check out the archived version once its processed. I think you will find it interesting ;)

Monday, November 5, 2012

Windows Memory Forensics Training for Analysts by Volatility Developers

We are please to announced the public offering of our Windows Memory Forensics for Analysts training course delivered by Volatility developers.

Information on the course and the December offering can be found on the Volatility Labs blog:

http://volatility-labs.blogspot.com/2012/11/windows-memory-forensics-training-for.html

Please contact me with any questions or comments.

Friday, October 12, 2012

Week 4 of the Month of Volatility Plugins posted!

I was writing to announce the last week of the month of Volatility plugins is finished, and we now have five more in-depth blog posts covering Windows and Linux internals and rootkit detection. These have all been posted on the Volatility Labs blog.

Post 1: Detecting Malware with GDI Timers and Callbacks

This posts covers analyzing malware samples that use timer callbacks to schedule actions.

http://volatility-labs.blogspot.com/2012/10/movp-41-detecting-malware-with-gdi.html

Post 2: Taking Screenshots from Memory Dumps

This posts covers the data structures and algorithms required to recreate the state of the screen (a screenshot) at the time of the memory capture.

http://volatility-labs.blogspot.com/2012/10/movp-43-taking-screenshots-from-memory.html

Post 3: Recovering Master Boot Records (MBRs) from Memory

This post covers recovering the MBR from memory and detecting bootkits.

http://volatility-labs.blogspot.com/2012/10/movp-43-recovering-master-boot-records.html

Post 4: Cache Rules Everything Around Me(mory)

This post covers a new plugin that can recover in-tact files from the Windows Cache Manager.

http://volatility-labs.blogspot.com/2012/10/movp-44-cache-rules-everything-around.html

Post 5: Phalanx 2 Revealed: Using Volatility to Analyze an Advanced Linux Rootkit

This post covers analyzing the Phalax2 rootkit with Volatility and other reversing tools.

http://volatility-labs.blogspot.com/2012/10/phalanx-2-revealed-using-volatility-to.html

This concludes the month of Volatlity, but do not fret, we have already posted a number of other non-MOVP posts and more are coming ;)