This program illustrates automatic techniques for locating 128-bit and 256-bit AES keys in a captured memory image.
The program uses various algorythms and also performs a simple entropy test to filter out blocks that are not keys. It counts the number of repeated bytes and skips blocks that have too many repeats.
This method works even if several bits of the key schedule have been corrupted due to memory decay.
|License||Verified by||Verified on||Notes|
|GPLv2orlater||Debian||20 March 2013|
|BSD 3Clause||Debian||20 March 2013|
Leaders and contributors
|Nadia Heninger Ariel Feldman||contact|
Resources and communication
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.3 or any later version published by the Free Software Foundation; with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts. A copy of the license is included in the page “GNU Free Documentation License”.
The copyright and license notices on this page only apply to the text on this page. Any software or copyright-licenses or other similar notices described in this text has its own copyright notice and license, which can usually be found in the distribution or license text itself.