Hello volatile users,
It's my first post, I'm not in the forensics Industry, I'm more like a
curious...
I'm very impressed with volatile system. Amazing project.
Someone know if there any any plan to add support to Windows 2003 in
Volatility? It should be awesome.
Speaking a bit about acquiring data. I use mdd in general. However I
always only copy a small amount of ram (256 mb in average), because
try copy the whole system memory result in crashes. There is anyway to
copy most data as possible without disrupt windows? In general, how do
you deal with this problem?
Thank you.
R.