Showing posts with label Volatility. Show all posts
Showing posts with label Volatility. Show all posts

Brand New & Improved Volatility Reporting Plugin

Guidance Software

Over the past couple of years the Guidance Software EnCase consultants and trainers have provided advice and assistance concerning how to manage the digital artifacts from RAM or memory analysis when using Volatility as their tool of choice. The two blog posts below provide insight into the progress.

Volatility Reporting Plugin for EnCase Forensic v7

Guidance Software

As most investigators know, volatile memory contains valuable information about the runtime state of the system, registry keys, network connections in memory and much more. One of the most popular tools to handle memory analysis is Volatility, an open source tool created by Volatile Systems.