Volatile Memory Col...
 
Notifications
Clear all

Volatile Memory Collection

8 Posts
6 Users
0 Reactions
406 Views
(@aperture)
New Member
Joined: 11 years ago
Posts: 3
Topic starter  

Hi All,

I have analysed a memory dump on a number of occasions but I haven't ever had to take one. I was wondering what people's thoughts on the best way to do this? I have had a look around and can't find many up to date resources, so any info would be really appreciated.

Thanks.


   
Quote
(@joe_t)
Active Member
Joined: 13 years ago
Posts: 14
 

Hi All,

I have analysed a memory dump on a number of occasions but I haven't ever had to take one. I was wondering what people's thoughts on the best way to do this? I have had a look around and can't find many up to date resources, so any info would be really appreciated.

Thanks.

On Windows? I've found that Belkasoft's Live RAM Capturer works very well and it's free.


   
ReplyQuote
Igor_Michailov
(@igor_michailov)
Honorable Member
Joined: 20 years ago
Posts: 529
 

Memory Forensics (Windows, Mac and Linux)
http//www.slideshare.net/suffert/2010-2013-sandro-suffert-memory-forensics-introdutory-work-shop-public#btnNext


   
ReplyQuote
(@aperture)
New Member
Joined: 11 years ago
Posts: 3
Topic starter  

Windows primarily yes. And I like free!

Thanks for the responses )


   
ReplyQuote
Bendroid
(@bendroid)
Eminent Member
Joined: 11 years ago
Posts: 35
 

Belkasofts tool is indeed working very well, great one. If you have OSForensics you can also use that, In conjunction with that little command line tool 'Volatilitiy' it's amazing.


   
ReplyQuote
ForensicRanger
(@forensicranger)
Estimable Member
Joined: 16 years ago
Posts: 122
 

Just remember that the RAM is just part of what you need…


   
ReplyQuote
(@aperture)
New Member
Joined: 11 years ago
Posts: 3
Topic starter  

Absolutely, we are set up for forensic collection, however we have not ventured too far into the realms of volatile memory, hence the question. Seems to be such a new field none of the team had any mention of it on various degrees/ post graduate courses. We have all used volatility and used it to give us some good hints in terms of where to look for malware on a forensic image, but that is relying on someone else providing us with the RAM capture.

I have tested out the Belkasoft tool - thanks for the recommendations, it is my favourite so far!


   
ReplyQuote
Adam10541
(@adam10541)
Honorable Member
Joined: 13 years ago
Posts: 550
 

Xways Forensics can capture the RAM as well I believe.


   
ReplyQuote
Share: