I remember years ago, I acquired a RAM image via FTK Imager, and I could not identify the malware within RAM. I then acquired via Belkasoft's RAM capture, and extracted no problem.
Is it still true FTK Imager does not get a complete capture? I remember it was a problem for years. Some of my colleagues promote using it.
_______________________________________________
Vol-users mailing list -- vol-users@lists.volatilityfoundation.org
To unsubscribe send an email to vol-users-leave@lists.volatilityfoundation.org
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
One-click Unsubscribe:
%(user_optionsurl)s?unsub=1&unsubconfirm=1