Hacker News new | ask | show | jobs
by chairmankaga 4133 days ago
"...the examiner found a hit in C:\Windows\MEMORY.DMP. This file stores debug information when a system failure occurs."

Seems to be generated on a previous system failure.

1 comments

More generally, the Forensics Wiki has a list of available memory imaging tools:

http://www.forensicswiki.org/wiki/Tools:Memory_Imaging

Anecdotally, I've heard from forensic practitioners that the KnTTools are very solid (and, importantly, unlikely to crash a running system during acquisition), but they're not free.