Forensic Memory Acquisition in Windows - FTK Imager

Поделиться
HTML-код
  • Опубликовано: 14 дек 2024

Комментарии • 18

  • @cartoonzfromlifecartoonani2074
    @cartoonzfromlifecartoonani2074 4 года назад +2

    You teach in a way that makes it easier to understand.Thank you for sharing what you know with us.

  • @Teletha
    @Teletha 5 лет назад +4

    you should also show how to read the data dump file

    • @DFIRScience
      @DFIRScience  5 лет назад

      There are many ways to read the data, depending on what you are trying to do. Check out this video on using Volatility to analyze the dump: ruclips.net/video/Cs0Gc3GtfZY/видео.html

  • @imperatork77
    @imperatork77 7 месяцев назад

    Thank you for your great video. I have a question what is the diference between .mem and .raw memory files? Can I obtain from FTK imager the .raw memory file?

  • @AhGanTsao
    @AhGanTsao 7 лет назад +3

    Very useful video, thank you sir.

  • @mxrcyprivate
    @mxrcyprivate 2 года назад +1

    why when i dump the memory from ftk my pc crashes

  • @saniyasayyed7685
    @saniyasayyed7685 4 года назад +1

    Thanks for an amazing tutorial it really helped me with my project. Keep going!

  • @kieranthart4527
    @kieranthart4527 4 года назад

    Very clear tutorial, thankyou.

  • @simon_969
    @simon_969 7 лет назад +1

    thank you this helps alot with my computer security course homework
    thanks!

    • @ko-Daegu
      @ko-Daegu 6 лет назад

      Simon Wu
      Is it for college???what major ???

  • @pourya1543
    @pourya1543 3 года назад

    I want to extract the "mem" file, can you help?

  • @nilotpalsaikia861
    @nilotpalsaikia861 5 лет назад

    Can I acces file type e01 .with ftk ?

  • @francoisfernandezrivadenei1229
    @francoisfernandezrivadenei1229 4 года назад

    I get an error that says "Couldn't start driver"

  • @AliAhmed-zk1qc
    @AliAhmed-zk1qc 6 лет назад

    you said we should not switch off the computer and collect the data in the memory unless we have special equipments, ruclips.net/video/1OxR4KLj-4I/видео.html . Is it possible to do that , what i know if you switch it off there will be zero chance to get the data that was in the memory. could you explain me what you meant ?

    • @DFIRScience
      @DFIRScience  6 лет назад

      Random Access Memory does looses a charge quickly once the computer has been powered off, but it is not instant in most cases. If you switch off the computer, turn it back in *immediately* any load a very small acquisition program, you may be able to recover some data. The longer the system is off, the less data will be available, and the more fragmentation/corruption you will get. I've seen studies say up to 10 minutes, but you get major data degradation way before that. Check out this paper on cold boot attacks: citp.princeton.edu/research/memory/

  • @isuruamalka2258
    @isuruamalka2258 4 года назад

    Plz tell me ftk full installation

  • @RoseWilson-u2t
    @RoseWilson-u2t 3 месяца назад

    Walker Dorothy Martinez Angela Robinson Jessica