WinPmem
As we mentioned previously, some memory acquisition tools work better with different memory analysis tools. In the case of the Rekall memory analysis tool, there are several memory acquisition tools provided by the same organization that created it. The PMEM tools that are available are used to capture raw memory from Linux, macOS, and Windows systems. These tools are available at the Rekall website: http://releases.rekall-forensic.com/.
In the following demonstration, the target system is the same one that was utilized in the FTK Imager demonstration. As a result, the WinPmem tool, which is specifically designed to capture the memory of Windows systems, will be utilized.
Starting with version 2.0.1, the default output for the WinPmem ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access