I have two tools installed, encase and x-way, my memory is 8G. and windows 7 64 bits
in encase, it asks me for physical memory or process memory during acquistion, if I choose physical memory, after acquire, i double click the acquired memory, but nothing happens
if I acquire process memory, my computer hangs for over 1 hour.
in X-ways, no memory acquisition available
my goal is to analyze memory for rootkit, anyone knows how to handle in Encase or x-ways? thanks
You can use FTK Imager or DumpIT. They are good tools for memory acquisition.
we have chosen only encase and x-ways to do our forensic, can't use other software
we have chosen only encase and x-ways to do our forensic, can't use other software
Which is good ) , as BOTH those commercial softwares have dedicated support, to which you may want to ask these questions.
jaclaz
Hi,
You can give a try to
I understand that you are required to use Encase or X-ways but I wanted to let you know just in case…
Thank you.