- Windows Forensics Cookbook
- Oleg Skulkin Scar de Courcier
- 108字
- 2021-07-02 20:57:40
Windows memory image analysis with Belkasoft Evidence Center
In the previous recipes, we successfully created two memory forensic images, one with Belkasoft Live RAM Capturer, and the other with DumpIt. Now it's time to perform analysis. Let's start from the first image and use Belkasoft Evidence Center for analysis.
Belkasoft Evidence Center is a powerful digital forensics tool, capable of parsing data not only from memory images, but also from images of computer drives and mobile devices. From a memory dump, it can extract valuable artifacts such as remnants of communications via social networks, messengers, chat rooms, webmail systems, data from cloud services, web-browsing artifacts, and so on.
推薦閱讀
- 深入核心的敏捷開發:ThoughtWorks五大關鍵實踐
- Java 9 Concurrency Cookbook(Second Edition)
- Python語言程序設計
- Kali Linux Wireless Penetration Testing Beginner's Guide(Third Edition)
- Learning Python by Building Games
- Learning ArcGIS for Desktop
- C# 8.0核心技術指南(原書第8版)
- Vue.js 2 Web Development Projects
- JavaEE架構與程序設計
- 算法訓練營:海量圖解+競賽刷題(入門篇)
- Python程序設計:基礎與實踐
- Web前端開發技術實踐指導教程
- 多接入邊緣計算實戰
- Java項目驅動開發教程
- 零基礎學西門子PLC編程:入門、提高、應用、實例