- Windows Forensics Cookbook
- Oleg Skulkin Scar de Courcier
- 108字
- 2021-07-02 20:57:40
Windows memory image analysis with Belkasoft Evidence Center
In the previous recipes, we successfully created two memory forensic images, one with Belkasoft Live RAM Capturer, and the other with DumpIt. Now it's time to perform analysis. Let's start from the first image and use Belkasoft Evidence Center for analysis.
Belkasoft Evidence Center is a powerful digital forensics tool, capable of parsing data not only from memory images, but also from images of computer drives and mobile devices. From a memory dump, it can extract valuable artifacts such as remnants of communications via social networks, messengers, chat rooms, webmail systems, data from cloud services, web-browsing artifacts, and so on.
推薦閱讀
- 演進式架構(原書第2版)
- 精通Nginx(第2版)
- Mastering JavaScript Object-Oriented Programming
- 造個小程序:與微信一起干件正經事兒
- Python數據分析基礎
- VMware vSphere 6.7虛擬化架構實戰指南
- Visual C++數字圖像處理技術詳解
- 你不知道的JavaScript(中卷)
- Mastering Predictive Analytics with Python
- PhoneGap:Beginner's Guide(Third Edition)
- Learning Vaadin 7(Second Edition)
- 從零開始學UI:概念解析、實戰提高、突破規則
- Learning Image Processing with OpenCV
- Python Linux系統管理與自動化運維
- 前端程序員面試算法寶典