Notifications
Clear all
06/03/2011 4:21 am
What OS is the memory dump from?
Memory analysis is a fledgling field. You are not likely to find nice pretty pieces of evidence. You will likely have to do some carving, some manual re-ssemble and some educated guessing. There are some options in FTK and EnCase for memory analysis. There are also some specialty tools like Volatility, Memoryze, Responder, etc. that you can use for some dumps.
Page 2 / 2
Prev