Digital Forensics Activity
Covers Windows volatile memory forensics to reconstruct user activity
Brought to you by:
dinesh9371
The reconstruction of the user activity is achieved by extracting the digital evidence from the Windows volatile memory dump. The digital evidence extracted consists of the Windows registry related information accessed by the running process.
Digital Forensics Analysis of Volatile Memory to Reconstruct User Activity