Windows memory acquisition with Belkasoft RAM Capturer
Belkasoft RAM Capturer is a free tool any digital forensic examiner should have in their kit. It's tiny, easy to use, and has the ability to acquire memory from Windows systems, including Windows 10, even if they are protected by an active anti-debugging or anti-dumping system.
Getting ready
You have two options for downloading the tool. If you are a Belkasoft customer and have a Belkasoft Evidence Center license, go to your customer portal, where you can find a Belkasoft RAM Capturer download link in the FREE PRODUCTS
section. If you are not a customer, just go to the DOWNLOAD
section on the Belkasoft website, choose the product you want to download - in our case, Belkasoft Live RAM Capturer - and fill in a short form with your contact information. After the download, a link will be sent to the email provided.
The steps to prepare a flash drive for acquisition are as follows:
- It must have enough space to store the memory image.
- It must be...