2. Memory Acquisition

Memory acquisition is the process of acquiring volatile memory (RAM) to non-volatile storage (file on the disk). There are various tools that allow you to acquire the memory of a physical machine. The following are some of the tools that allow you to acquire (dump) the physical memory onto Windows. Some of these tools are commercial, and many of them can be downloaded for free after registration. The following tools work with both x86 (32-bit) and x64 (64-bits) machines:

Get Learning Malware Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.