Live Forensic RAM analysis Windows 10 - FTK Imager - Extract and recover jpeg picture file from RAM.

Описание к видео Live Forensic RAM analysis Windows 10 - FTK Imager - Extract and recover jpeg picture file from RAM.

Live Forensic
In this short video, we will use FTK Imager to extract and recover a jpeg picture file from the RAM acquisition memory dump for forensic investigation purposes.

FTK Imager is a free accessible forensic analysts and incident responders tool created by AccessData, now known as Exterro company.

You can download and install the FTK imager from https://www.exterro.com/ftk-imager to your machine or USB drive.

For the list of file signatures https://en.wikipedia.org/wiki/List_of...
For the JPEG Signature Format: Introduction & Recovery
https://www.ntfs.com/jpeg-signature-f...

Комментарии

Информация по комментариям в разработке