- Windows Forensics Cookbook
- Oleg Skulkin Scar de Courcier
- 54字
- 2021-07-02 20:57:39
How it works…
Belkasoft RAM Capturer operates in kernel mode (not in user mode like some other acquisition tools) with the help of 32-bit and 64-bit kernel drivers. It extracts the whole physical memory, even if it's protected, in a forensically sound manner, and saves it into a file with the .mem extension.
推薦閱讀
- JMeter 性能測(cè)試實(shí)戰(zhàn)(第2版)
- 人人都是網(wǎng)站分析師:從分析師的視角理解網(wǎng)站和解讀數(shù)據(jù)
- Jupyter數(shù)據(jù)科學(xué)實(shí)戰(zhàn)
- jQuery炫酷應(yīng)用實(shí)例集錦
- INSTANT Yii 1.1 Application Development Starter
- Access 2010數(shù)據(jù)庫應(yīng)用技術(shù)實(shí)驗(yàn)指導(dǎo)與習(xí)題選解(第2版)
- MySQL 8從零開始學(xué)(視頻教學(xué)版)
- Hands-On Robotics Programming with C++
- Building Business Websites with Squarespace 7(Second Edition)
- Web前端測(cè)試與集成:Jasmine/Selenium/Protractor/Jenkins的最佳實(shí)踐
- 前端架構(gòu)設(shè)計(jì)
- Ubuntu Server Cookbook
- C語言從入門到精通(視頻實(shí)戰(zhàn)版)
- Backbone.js Patterns and Best Practices
- HTML5 Game Development by Example:Beginner's Guide(Second Edition)