live acquisition fo...
 
Notifications
Clear all

live acquisition for registry

11 Posts
6 Users
0 Reactions
1,964 Views
(@mrwh1t3)
Eminent Member
Joined: 15 years ago
Posts: 41
 

Capture it using FTK Imager and then pull the reg keys out using volatility. You can extract reg hives using volatility one windows and some linux systems as well.

Good luck!


   
ReplyQuote
Page 2 / 2
Share: