2.1 Memory Acquisition Using DumpIt

DumpIt is an excellent memory acquisition tool that allows you to dump physical memory on Windows. It supports the acquisition of both 32-bit (x86) and 64-bit (x64) machines. DumpIt is part of a toolkit called the Comae memory toolkit, which consists of various standalone tools that assist with memory acquisition and conversion between different file formats. To download the latest copy of the Comae memory toolkit, you need to create an account by registering on https://my.comae.io. Once the account is created, you can log in and download the latest copy of the Comae memory toolkit.

After downloading the Comae toolkit, extract the archive, and navigate to the 32-bit or 64-bit directory, depending on whether ...

Get Learning Malware Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.