The steps for Windows memory image analysis using Belkasoft Evidence Center:
- To do that, click on New in the Open Case window. Now you need to fill in a few fields:
- Case name - Usually, we use the case number and year for case names, but this time, as it's being created for testing purposes, we will name it Belkasoft Memory Forensics Test.
- Root folder - Here, you should choose the folder where the case data will reside. In our case it's D: drive.
- Case folder - This field will be filled in automatically based on the two previous fields, so in our case, it's D:\Belkasoft Memory Forensics Test.
- Investigator - Type your name in this field.
- Time zone - Choosing the right time zone is very important. If you already know the right ...