Technical requirements
In this chapter, we will work with memory acquisition and analysis tools. Using the following links, you can access and download them, and installation is fairly straightforward:
- FTK Imager: https://www.exterro.com/ftk-imager
- Volatility: https://www.volatilityfoundation.org/releases
- WinPmen: https://github.com/Velocidex/WinPmem
- DumpIt: https://zeltser.com/memory-acquisition-with-dumpit-for-dfir-2/
- Belkasoft RAM Capturer: https://belkasoft.com/ram-capturer
- MAGNET RAM Capture: https://support.magnetforensics.com/s/software-and-downloads?productTag=free-tools