Memory acquisition and the pagefile(s)
Written by Jamie Butler
In the past, I have discussed how in reality there may be as many as 16 pagefiles on a single host. The next question is, “How much data could be contained in all these pagefiles”? Why does this matter? Well, the more data in the pagefiles, the longer they will take to acquire. Read the rest
Tags: memory acquisition, pagefiles, swap files, Training
Live analysis and its footprint
Written by Jamie Butler
Recently there was a conversation on Harlan’s Windows Incident Response blog which mentioned the footprint of Memoryze and other tools. Every tool has positives and negatives depending on the use case.
First, the blog entry mainly mentions the footprint on disk, which is larger than other acquisition tools because Memoryze does both acquisition and analysis in the same package. Read the rest
Tags: live analysis, live response, Matthieu Suiche, memory acquisition, Memory analysis, Memoryze, Windows Incident Response

