Acquiring memory with Magnet RAM Capture
Magnet Forensics also released its own free memory acquisition tool, called Magnet RAM Capture, which can be used to acquire memory from Windows systems. To extract the physical memory, Magnet RAM Capture uses a kernel-mode driver. It creates memory dumps in raw format, which is supported by both open source memory forensic tools and full-featured digital forensic suites.
To download Magnet RAM Capture, take the following steps:
- Go to the RESOURCES tab and then the FREE TOOLS tab on the official Magnet Forensics web page at https://www.magnetforensics.com/.
- Choose MAGNET RAM CAPTURE and fill in a short form. After confirmation, you will receive a download link. After downloading, copy
MRCv120.exe
to your flash drive.
Dumping memory with Magnet RAM Capture is very easy and straightforward, as the following instructions show:
- Connect the flash drive to the target system and run
MRCv120.exe
as Administrator.
...