Comparison of Memory Acquisition Software for Windows

1. Methodology

Image for post
Image for post
The tools

1.1 Output

Image for post
Image for post
DumpIt
Image for post
Image for post
Live RAM Capturer
Image for post
Image for post
FTK Imager
Image for post
Image for post
Magnet RAM Capture
Image for post
Image for post
Image for post
Image for post

2. Discussion

2.1 User interface and customizability

Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post

2.2 Acquisition time

Image for post
Image for post
Acquisition time
Image for post
Image for post
DumpIt .json
Image for post
Image for post
DumpIt
Image for post
Image for post
Belkasoft RAM Capturer
Image for post
Image for post
FTK Imager
Image for post
Image for post
Magnet RAM Capture

2.3 Occupied memory according to Task Manager

Image for post
Image for post
Memory usage according to Task Manager
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post
Image for post

2.4 Loaded DLLs

Image for post
Image for post
Loaded DLLs

2.5 Registry changes and invoked files

Image for post
Image for post
Registry changes and invoked files

2.6 Portable software

Image for post
Image for post
Portable software

3. Evaluation

Image for post
Image for post
Evaluation

References

Written by

Philosophy | Poetry

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store