Skip to content

demize's blog

Copy-Robust

Imagine, for a minute, that you're an incident response analyst and you've just finished a memory dump on a machine you suspect was infected with malware. This is a laptop that's assigned to someone who works remotely from (you have to assume) the goddamn moon, because their network connection is both incredibly slow and even more unreliable. You've tried to copy the memory dump off using your EDR solution. It keeps failing because of the awful network connection.

That's the situation I found myself in when I wrote this script.