@MASTERSTHESIS\{IMM2015-07061, author = "A. R. Simal", title = "Automation of memory-based {IOC} analysis", year = "2015", school = "Technical University of Denmark, Department of Applied Mathematics and Computer Science", address = "Richard Petersens Plads, Building 324, {DK-}2800 Kgs. Lyngby, Denmark, compute@compute.dtu.dk", type = "", note = "{DTU} supervisors: Robin Sharp and Christian D. Jensen, cdje@dtu.dk, {DTU} Compute", url = "http://www.compute.dtu.dk/english", abstract = "The purpose of this thesis is to identify and implement an automation system over the Volatility platform, providing a way to analyze memory images from an array of hosts in an efficient manner, with the goal of detecting indicators of compromise (IoC) within them, among a set of predefined malware traits. To achieve this, an organizational context is assumed, where there’s an infrastructure of hosts within a typology, sharing therefore a set of security policies, allowing the {IT} security manager to effectively maintain and verify the compliance of the latter, as well as to respond to an incident in an efficient way." }