- Windows Forensics Cookbook
- Oleg Skulkin Scar de Courcier
- 81字
- 2025-02-24 18:56:52
Windows memory acquisition with DumpIt
DumpIt is a free memory imaging tool from Comae Memory Toolkit. It's a fusion of Win32dd and Win64dd in one executable. It's extremely easy to use: even a non-technical person can use it in emergency situations. DumpIt supports all modern Windows versions, from XP to 10, both 32 and 64-bit. Also, the tool has a very important feature: it displays the Directory Table Base and the address of the debugging data structures during the acquisition process.