Study on Live analysis of Windows Physical Memory

Divyang Rahevar · IOSR Journal of Computer Engineering · 2013

Memory forensics and data carving methods are usually used during volatile investigation and is nowadays a big area of interest. Volatile memory dump is used for offline analysis of live data. Live analysis of the running system gives the information of which events are going on. Volatile memory analysis can give the sensitive information such as User Ids, Passwords, Hidden Processes, Root kits, Sockets etc. which are not stored on the physical drive. This Paper represents various approaches and tools used to capture and analyse data from computer memory.

Read the paper · More papers on PaperTik