- Windows Forensics Cookbook
- Oleg Skulkin Scar de Courcier
- 108字
- 2021-07-02 20:57:40
Windows memory image analysis with Belkasoft Evidence Center
In the previous recipes, we successfully created two memory forensic images, one with Belkasoft Live RAM Capturer, and the other with DumpIt. Now it's time to perform analysis. Let's start from the first image and use Belkasoft Evidence Center for analysis.
Belkasoft Evidence Center is a powerful digital forensics tool, capable of parsing data not only from memory images, but also from images of computer drives and mobile devices. From a memory dump, it can extract valuable artifacts such as remnants of communications via social networks, messengers, chat rooms, webmail systems, data from cloud services, web-browsing artifacts, and so on.
推薦閱讀
- Deploying Node.js
- C語言程序設計(第2 版)
- Three.js開發指南:基于WebGL和HTML5在網頁上渲染3D圖形和動畫(原書第3版)
- Mastering Yii
- C語言程序設計案例精粹
- JavaScript 程序設計案例教程
- Yocto for Raspberry Pi
- Working with Odoo
- Instant Nancy Web Development
- Scala Reactive Programming
- PHP從入門到精通(第4版)(軟件開發視頻大講堂)
- SSM開發實戰教程(Spring+Spring MVC+MyBatis)
- 響應式Web設計:HTML5和CSS3實戰(第2版)
- Buildbox 2.x Game Development
- R語言:邁向大數據之路(加強版)