FTK Imager

Access Data's FTK Imager is a Windows software platform that performs a variety of imaging tasks including acquiring the running memory of a system. The software can be downloaded at http://accessdata.com/product-download/digital-forensics/ftk-imager-version-3.4.3. Once downloaded, install the executable in the Tools partition of the USB drive. Open the FTK Imager folder and run the executable as administrator. The following window will appear:

Click on File and then on Capture Memory. This opens up the following window:

Browse to ...

Get Digital Forensics and Incident Response now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.