- Windows Forensics Cookbook
- Oleg Skulkin Scar de Courcier
- 169字
- 2021-07-02 20:57:39
How to do it…
The steps for Windows memory acquisition using Belkasoft Ram Capturer are as follows:
- The first thing you must do is learn what kind of system you are dealing with x32 or x64. It's really easy to do right-click Computer and choose Properties. In our case, it's x64. So our choice is RamCapture64.exe.
- After starting, we will get information about the physical memory page size and its total size.
- Now select the output folder path make sure it's your flash drive and not the local system drive.
- After that just click Capture!

Figure 2.2. Memory acquisition with Belkasoft RAM Capturer
As a result, we get a file with .mem extension of the same size as the total physical memory. By default, you have the date of acquisition as the filename, but we highly recommend renaming it, and adding more information for identification purposes: operating system version, edition, computer name, and other information.
That's it! The image is ready for further analysis with memory forensics tools.
推薦閱讀
- Java程序設計與開發
- Spring 5.0 Microservices(Second Edition)
- Testing with JUnit
- HTML5+CSS3網頁設計
- Java 9模塊化開發:核心原則與實踐
- 寫給大家看的Midjourney設計書
- NGUI for Unity
- Clojure High Performance Programming(Second Edition)
- Instant GLEW
- Keil Cx51 V7.0單片機高級語言編程與μVision2應用實踐
- Monitoring Docker
- Offer來了:Java面試核心知識點精講(框架篇)
- Microsoft XNA 4.0 Game Development Cookbook
- ASP.NET Core 2 High Performance(Second Edition)
- Three.js Essentials