Professional Documents
Culture Documents
DIGITAL FORENSICS
AIM- Capture the Memory of any OS System and try to
analyse .mem file on Kali using Volatility tool
DATE: 06-02-2021
_______________________________________________
PART 1- To create Windows memory dump using FTK Imager
STEP 1- Open and run FTK Imager Tool.
STEP 2- Go in the File option and select Capture Memory option
STEP 3- Set Destination Path to save the memory dump.
___________________________________________________________________________