Notifications
Clear all

FTK Memory Dump

11 Posts
6 Users
0 Reactions
2,730 Views
(@dndschultz)
Eminent Member
Joined: 15 years ago
Posts: 24
Topic starter  

When would you import a memory dump?


   
Quote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Any time you seize a running computer?

If you suspect there is evidence in RAM, dump the memory. Otherwise you risk losing on any remotely modern machine at least 512MB of evidence.

And evidence can mean a lot of things so have a plan.


   
ReplyQuote
(@dndschultz)
Eminent Member
Joined: 15 years ago
Posts: 24
Topic starter  

So I would have to have FTK on a thumb drive and dump the RAM before the computer is unplugged?


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

FTK Imager. You can have it on a thumb drive or a CD if you have a collection drive.


   
ReplyQuote
(@dndschultz)
Eminent Member
Joined: 15 years ago
Posts: 24
Topic starter  

Sorry, I'm still a bit confused. Would you do a memory dump in the field every time you seize a computer or just when you think something is important and may be lost when you unplug and transport to your forensics lab?


   
ReplyQuote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

Greetings,

If the information is available, and I am legally entitled to collect it, I will. Worst case scenario, I don't use it. Take the extra bit of time and get everything.

-David


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

I second this.

I rather have more and later discard, than less and hem and haw…

Greetings,

If the information is available, and I am legally entitled to collect it, I will. Worst case scenario, I don't use it. Take the extra bit of time and get everything.

-David


   
ReplyQuote
 96hz
(@96hz)
Estimable Member
Joined: 17 years ago
Posts: 143
 

Dependant on what you are investigating, the memory could contain some very valuable information.

As has already been said if its available and lawful, it could be worth getting. If there's whole disk encryption it could be vital, if you need to know what processes were running or ports were open it could be vital.

If the computers off when you arrive at the scene, its probably not worth turning it on to get it wink


   
ReplyQuote
mrpumba
(@mrpumba)
Estimable Member
Joined: 15 years ago
Posts: 116
 

I collected the memory on a test computer using FTK imager 2.9, which created memdump.mem. Now that I have it how do I review the file and what was captured?


   
ReplyQuote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

Greetings,

Try Volitility - https://www.volatilesystems.com/default/volatility

-David


   
ReplyQuote
Page 1 / 2
Share: