官术网_书友最值得收藏!

How to do it…

The steps for Windows memory acquisition using Belkasoft Ram Capturer are as follows:

  1. The first thing you must do is learn what kind of system you are dealing with x32 or x64. It's really easy to do right-click Computer and choose Properties. In our case, it's x64. So our choice is RamCapture64.exe.
  2. After starting, we will get information about the physical memory page size and its total size.
  3. Now select the output folder path make sure it's your flash drive and not the local system drive.
  4. After that just click Capture!
Figure 2.2. Memory acquisition with Belkasoft RAM Capturer

As a result, we get a file with .mem extension of the same size as the total physical memory. By default, you have the date of acquisition as the filename, but we highly recommend renaming it, and adding more information for identification purposes: operating system version, edition, computer name, and other information.

That's it! The image is ready for further analysis with memory forensics tools.

主站蜘蛛池模板: 抚松县| 田东县| 新竹市| 泸定县| 林西县| 黄梅县| 自贡市| 神木县| 宁夏| 全南县| 康平县| 竹北市| 明星| 鄯善县| 涿州市| 石城县| 古田县| 莱芜市| 民权县| 崇义县| 长治县| 文水县| 前郭尔| 越西县| 南康市| 察哈| 嘉荫县| 银川市| 木兰县| 双江| 宁乡县| 汉沽区| 南漳县| 隆德县| 临江市| 松滋市| 简阳市| 文安县| 无棣县| 大悟县| 白水县|