Another option that is available to incident response analyst is the use of the tool F-Response. F-Response is a software platform that allows incident response analysts to perform remote acquisition of evidence over a network. One advantage to utilizing F-Response is that it does not require direct access via SSH or RDS to the remote system. Another key feature of F-Response is that the tool is designed to establish the connection while allowing the incident response analyst to utilize their preferred tools to perform the acquisition.
In the following example, F-Response is utilized to connect to a suspected compromised system over a network whereby the incident response analyst can utilize FTK Imager to acquire the memory of ...