O'Reilly logo

Windows Forensics Cookbook by Scar de Courcier, Oleg Skulkin

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

How to do it...

The steps for Windows memory image analysis using Belkasoft Evidence Center:

  1. To do that, click on New in the Open Case window. Now you need to fill in a few fields:
    • Case name - Usually, we use the case number and year for case names, but this time, as it's being created for testing purposes, we will name it Belkasoft Memory Forensics Test.
    • Root folder - Here, you should choose the folder where the case data will reside. In our case it's D: drive.
    • Case folder - This field will be filled in automatically based on the two previous fields, so in our case, it's D:\Belkasoft Memory Forensics Test.
    • Investigator - Type your name in this field.
    • Time zone - Choosing the right time zone is very important. If you already know the right ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required