Home
Search
Taxonomy
Developers
Contacts
Forensic Tool Functionalities
Cloud Services
Data Analytics
Database Forensics
Deleted File Recovery
Disk Cataloging
Disk Imaging
Drone Forensics
Email Parsing
File Carving
Forensics Boot Environment
Forensic File Copy
Forensic Tool Suite (Mac Investigations)
Forensic Tool Suite (Windows Investigations)
GPS Forensics
Hardware Write Block
Hash Analysis
Image Analysis (Video & Graphics Files)
Incident Response Forensic Tracking & Reporting
Infotainment & Vehicle Forensics
Instant Messenger
Live Response
Media Sanitization/Drive Re-use
Memory Capture and Analysis
Mobile Device Acquisition, Analysis and Triage
P2P Analysis
Password Recovery
Remote Capabilities / Remote Forensics
Social Media
Software Write Block
Steganalysis
String Search
Tool Validation
Video Analytics
Video Format Conversion
VoIP Forensics
Web Browser Forensics
WiFi Forensics
Windows Registry Analysis
Open Source Intelligent Tool
Suggest new Forensic Tool Functionality
Home
> Search
Searching for forensic tools and techniques by
functionality
Find all Memory Capture and Analysis tools and techniques
Refine by search parameters
Forensic Functionality:
Memory Capture and Analysis
Description:
No description available.
Technical Parameters:
Tool support for binary RAM dump:
Tool support for memory analysis:
Supported extractable memory objects:
any
N/A
Tool support for binary RAM dump
Binary RAM dump unsupported
any
N/A
Tool support for memory analysis
Memory analysis unsupported
any
N/A
process list
process status (active, hidden, or exited)
processes as .exe files
EPROCESS list
kernel module list
driver list
DLL lists
TCPT_OBJECTs
open handles
open files by process
open registry handles by process
open network sockets
open network connections
TCP connections
passwords
browser artifacts (e.g., in-private browsing history)
cloud service artifacts (e.g., Dropbox, Flickr, Google Drive)
social network artifacts
webmail artifacts (e.g., GMail, Hotmail, Yahoo)
P2P remnants
Instant Messenger histories
n/a (binary RAM dump only)