MENU

Posts Tagged ‘DumpIt’

Most Recent
 
Read More
2017-08-17

Virtual Machines Memory Forensics

Jason Hale talks about Memory Acquisition and Virtual Secure Fashion. «Physical memory is commonly acquired using a software-based memory acquisition tool such as winpmem, DumpIt, Magnet RAM Capturer, FTK Imager, or one of the several other options available. These tools typically load a device driver into the kernel and subsequently read memory through mapping the \\Device\PhysicalMemory object, using a function such as MmMapIoSpace, or directly manipulating the page tables. Many of these tools also share a similar trait: their use on a system with virtual secure mode enabled results in a system crash.».

486
 
Read More
2016-09-23

Your favorite Memory Toolkit is back!

“Due to popular demand, the your favorite and most popular memory forensics acquisition tools are back ! And for free!” – Matt Suiche.

287
Latest Headlines
 
Read More
875
 
Read More
460
 
Read More
893

Trending Topics
digital forensics
computer forensics
Articles
mobile forensics
DFIR
Android forensics
digital forensics software
windows forensics
forensic data recovery
Top Stories
 
 
Right Now
 
bstrings 1.0 released
Top Five
Heat Index
 
1
Decrypting encrypted WhatsApp databases without the key
 
2
How to Make the Forensic Image of the Hard Drive
 
3
Extracting data from SmartSwitch backups
 
4
Forensic tools for your Mac
 
5
Android forensic analysis with Autopsy

Get Help Now

Thank you for contacting us.
Your Digital Investigator will call you shortly.