Encase Enterprise P...
 
Notifications
Clear all

Encase Enterprise Phyiscal Memory Capture

3 Posts
2 Users
0 Reactions
621 Views
(@pisonic)
Active Member
Joined: 16 years ago
Posts: 6
Topic starter  

hi,

would like to check for those using Encase Enterprise to do remote capture of the physical memory over the network, after the output, what kind of analysis tools do u use to analyse the E01 file?


   
Quote
(@joachimm)
Estimable Member
Joined: 17 years ago
Posts: 181
 

hi,

would like to check for those using Encase Enterprise to do remote capture of the physical memory over the network, after the output, what kind of analysis tools do u use to analyse the E01 file?

I'm not sure if the Enterprise version is much different to the Forensic version in that regard, but you could try the following
* The Volatility Framework has embedded memory-E01 support.
* You could also dump the contents of the memory E01 to RAW, e.g. ewfexport, and select any tool you prefer.


   
ReplyQuote
(@pisonic)
Active Member
Joined: 16 years ago
Posts: 6
Topic starter  

thanks!


   
ReplyQuote
Share: