Sandman Version 1.0.080226

By Andreas Schuster
Copyright © 2008 int for(ensic){blog;}. All rights reserved. Reproduction for commercial purposes (including online advertisement) interdicted.

Matthieu Suiche and Nicolas Ruff have just released their first public version of the Sandman Framework.

Sandman parses the hibernation file. As it can be seen from a sample program, only a few lines of Python code suffice to convert the hibernation file into a raw ("dd-style") memory image.

Download the Sandman Framework here.

Forensic Science communications