Notifications
Clear all

FTK Memory Dump

11 Posts
6 Users
0 Reactions
2,731 Views
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

What OS is the memory dump from?

Memory analysis is a fledgling field. You are not likely to find nice pretty pieces of evidence. You will likely have to do some carving, some manual re-ssemble and some educated guessing. There are some options in FTK and EnCase for memory analysis. There are also some specialty tools like Volatility, Memoryze, Responder, etc. that you can use for some dumps.


   
ReplyQuote
Page 2 / 2
Share: