Looking for a progr...
 
Notifications
Clear all

Looking for a program to sort ram threads/processes etc..

3 Posts
3 Users
0 Reactions
617 Views
(@dr-zoidberg)
Active Member
Joined: 17 years ago
Posts: 11
Topic starter  

Hello,

I have been using winen to image memory on my pc. I was wondering if there are any programs which can retrieve thread, processes and object headers in a clearer format? Maybe not retrieve data from memory itself but from the encase image.

Thanks.8)


   
Quote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Check out Volatility Framework.


   
ReplyQuote
(@jeffcaplan)
Trusted Member
Joined: 21 years ago
Posts: 97
 

To my knowledge, Volatility doesn't support EnCase image file formats, only raw ones. If you've used WinEn to capture memory, you'll need to run it through FTK Imager and convert it to a raw style image and then you can use some of the open-source tools out there to analyze memory.


   
ReplyQuote
Share: