官术网_书友最值得收藏!

How to do it…

The steps for Windows memory acquisition using Belkasoft Ram Capturer are as follows:

  1. The first thing you must do is learn what kind of system you are dealing with x32 or x64. It's really easy to do right-click Computer and choose Properties. In our case, it's x64. So our choice is RamCapture64.exe.
  2. After starting, we will get information about the physical memory page size and its total size.
  3. Now select the output folder path make sure it's your flash drive and not the local system drive.
  4. After that just click Capture!
Figure 2.2. Memory acquisition with Belkasoft RAM Capturer

As a result, we get a file with .mem extension of the same size as the total physical memory. By default, you have the date of acquisition as the filename, but we highly recommend renaming it, and adding more information for identification purposes: operating system version, edition, computer name, and other information.

That's it! The image is ready for further analysis with memory forensics tools.

主站蜘蛛池模板: 信阳市| 河池市| 肇源县| 赤水市| 都兰县| 喜德县| 恩施市| 溧水县| 东宁县| 策勒县| 宜章县| 新河县| 绥宁县| 西畴县| 北京市| 平阳县| 独山县| 皮山县| 容城县| 吉安市| 原阳县| 西和县| 仙居县| 威海市| 怀仁县| 嵊泗县| 资兴市| 永嘉县| 阜宁县| 楚雄市| 秭归县| 枞阳县| 克拉玛依市| 仪陇县| 英德市| 章丘市| 泗水县| 鄯善县| 兴仁县| 晋江市| 闻喜县|