• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

In-Depth Analysis of Computer Memory Acquisition Software for Forensic Purposes.

作者信息

McDown Robert J, Varol Cihan, Carvajal Leonardo, Chen Lei

机构信息

Department of Computer Science, Sam Houston State University, 1903 Ave I, Huntsville, TX, 77341.

出版信息

J Forensic Sci. 2016 Jan;61 Suppl 1:S110-6. doi: 10.1111/1556-4029.12979. Epub 2015 Nov 17.

DOI:10.1111/1556-4029.12979
PMID:27405017
Abstract

The comparison studies on random access memory (RAM) acquisition tools are either limited in metrics or the selected tools were designed to be executed in older operating systems. Therefore, this study evaluates widely used seven shareware or freeware/open source RAM acquisition forensic tools that are compatible to work with the latest 64-bit Windows operating systems. These tools' user interface capabilities, platform limitations, reporting capabilities, total execution time, shared and proprietary DLLs, modified registry keys, and invoked files during processing were compared. We observed that Windows Memory Reader and Belkasoft's Live Ram Capturer leaves the least fingerprints in memory when loaded. On the other hand, ProDiscover and FTK Imager perform poor in memory usage, processing time, DLL usage, and not-wanted artifacts introduced to the system. While Belkasoft's Live Ram Capturer is the fastest to obtain an image of the memory, Pro Discover takes the longest time to do the same job.

摘要

相似文献

1
In-Depth Analysis of Computer Memory Acquisition Software for Forensic Purposes.
J Forensic Sci. 2016 Jan;61 Suppl 1:S110-6. doi: 10.1111/1556-4029.12979. Epub 2015 Nov 17.
2
Forensic analysis of anti-forensic file-wiping tools on Windows.Windows 上反取证文件擦除工具的法医分析。
J Forensic Sci. 2022 Mar;67(2):562-587. doi: 10.1111/1556-4029.14907. Epub 2021 Oct 7.
3
We are meeting on Microsoft Teams: Forensic analysis in Windows, Android, and iOS operating systems.我们正在微软团队上开会:关于Windows、安卓和iOS操作系统中的法医分析。
J Forensic Sci. 2023 Mar;68(2):434-460. doi: 10.1111/1556-4029.15208. Epub 2023 Feb 3.
4
A reference database of Windows artifacts for file-wiping tool execution analysis.
J Forensic Sci. 2023 May;68(3):856-870. doi: 10.1111/1556-4029.15240. Epub 2023 Apr 5.
5
A Forensic Exploration of the Microsoft Windows 10 Timeline.对微软Windows 10时间线的法证探索
J Forensic Sci. 2019 Mar;64(2):577-586. doi: 10.1111/1556-4029.13875. Epub 2018 Jul 26.
6
MATtrack: A MATLAB-Based Quantitative Image Analysis Platform for Investigating Real-Time Photo-Converted Fluorescent Signals in Live Cells.MATtrack:一个基于MATLAB的定量图像分析平台,用于研究活细胞中的实时光转换荧光信号。
PLoS One. 2015 Oct 20;10(10):e0140209. doi: 10.1371/journal.pone.0140209. eCollection 2015.
7
Assessment of freeware programs for the reconstruction of tomography datasets obtained with a monochromatic synchrotron-based X-ray source.基于单色同步辐射X射线源获得的断层扫描数据集重建的免费软件程序评估。
J Synchrotron Radiat. 2015 Jul;22(4):1130-8. doi: 10.1107/S1600577515008437. Epub 2015 Jun 24.
8
USB Storage Device Forensics for Windows 10.适用于Windows 10的USB存储设备取证
J Forensic Sci. 2018 May;63(3):856-867. doi: 10.1111/1556-4029.13596. Epub 2017 Jul 18.
9
Development of a user-friendly system for image processing of electron microscopy by integrating a web browser and PIONE with Eos.通过将网络浏览器和PIONE与Eos集成,开发一种用户友好的电子显微镜图像处理系统。
Microscopy (Oxf). 2014 Nov;63 Suppl 1:i32-i33. doi: 10.1093/jmicro/dfu070.
10
ChiMS: Open-source instrument control software platform on LabVIEW for imaging/depth profiling mass spectrometers.ChiMS:基于LabVIEW的用于成像/深度剖析质谱仪的开源仪器控制软件平台。
Rev Sci Instrum. 2015 Jun;86(6):065106. doi: 10.1063/1.4922913.