How to do it...

The steps for Windows memory image analysis using Belkasoft Evidence Center:

  1. To do that, click on New in the Open Case window. Now you need to fill in a few fields:
    • Case name - Usually, we use the case number and year for case names, but this time, as it's being created for testing purposes, we will name it Belkasoft Memory Forensics Test.
    • Root folder - Here, you should choose the folder where the case data will reside. In our case it's D: drive.
    • Case folder - This field will be filled in automatically based on the two previous fields, so in our case, it's D:\Belkasoft Memory Forensics Test.
    • Investigator - Type your name in this field.
    • Time zone - Choosing the right time zone is very important. If you already know the right ...

Get Windows Forensics Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.