Windows Forensics Cookbook
上QQ阅读APP看书,第一时间看更新

Windows memory acquisition with Belkasoft RAM Capturer

Belkasoft RAM Capturer is a free tool any digital forensic examiner should have in their kit. It's tiny, easy to use, and has the ability to acquire memory from Windows systems, including Windows 10, even if they are protected by an active anti-debugging or anti-dumping system.