Memory Dump Formats

As in other storage devices, volatile memory also has several formats. According to the acquisition method that is in use, the captured file format can be vary. According to (Ligh et al, 2018) the most commonly used memory dump formats are:

– RAW memory dump.
– Windows crash dump.
– Windows hibernation files.
– Expert witness format (EWF).
– HPAK format.

Raw memory dump is the most commonly used memory dump format by modern analysis tools. According to (Ligh et al, 2018) these raw file formatted memory dumps do not contain headers, metadata, or magic values.

Read More

Leave a Comment