Acquiring memory using FTK Imager
Memory is a very important source of evidence in an investigation process. All activities that happen on a system are usually reflected in the memory at the time.
The following is a step-by-step guide to acquire a system's volatile memory using the product FTK Imager.
This can be downloaded for free at http://accessdata.com/product-download.
- Run FTK Imager as an administrator, as shown in the following screenshot:
- Click on the File menu and select Capture Memory, as shown in the following screenshot:
- Browse the destination ...
Get Learning Network Forensics now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.