Windows Pagefile Collection and Analysis for a Live Forensics Context
Seok‐Hee Lee, Antonio Savoldi, Sangjin Lee, Jongin Lim · 2007
The aim of this paper is to present a new tool, the Page-file Collection Tool (PCT), which can be used to obtain a pagefile on a live Windows based system. It is a known fact that a pagefile on a live system is protected by the operating system, which uses it in the virtual memory context. By using the NTFS filesystem specifications we were able to reconstruct the full pagefile, which can be used by a forensics expert to carve out further and precious information in the memory analysis field.