Memory Dump Acquiring RAM using FTK Imager for Windows 10, Live Forensics, Ping activity within RAM

Опубликовано: 17 Октябрь 2024
на канале: CyDig Cyber Security Digital Forensics Education
4,528
59

Live Forensics
In this short video, I will show you how to get a memory dump or a copy of the RAM within a running Windows 10 machine. Then you can use this dump file for live digital forensic investigation using Volatility or any other tool.

Also, we found network ping activity within the RAM memory dump.

FTK Imager is a free accessible forensic analysts and incident responders tool created by AccessData, now known as Exterro company.

You can download and install the FTK imager from https://www.exterro.com/ftk-imager to your machine or USB drive.