{"repo":"LETHAL-FORENSICS/Collect-MemoryDump","free":true,"listed":false,"github":"https://github.com/LETHAL-FORENSICS/Collect-MemoryDump","clone":"git clone https://github.com/LETHAL-FORENSICS/Collect-MemoryDump.git","description":"Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR","language":"PowerShell","stars":265,"topics":["powershell","dfir","digital-forensics","incident-response","live-response","memory-acquisition","memory-forensics"],"license":"GPL-3.0","category":"cli-tools","readme_excerpt":"Collect-MemoryDump Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR Collect-MemoryDump.ps1 is a PowerShell script utilized to collect a Memory Snapshot from a live Windows system (including Pagefile Collection) in a forensically sound manner. Features: ARM64 Support (MAGNET DumpIt for Windows and MAGNET Response) Checks for Hostname and Physical Memory Size before starting memory acquisition Checks if you have enough free disk space to save memory dump file Collects a Microsoft Crash Dump w/ MAGNET DumpIt for Windows Collects a Raw Physical Memory Dump w/ MAGNET DumpIt, MAGNET RAM Capture, Belkasoft Live RAM Capturer and WinPMEM Pagefile Collection w/ MAGNET Response &#8594; very useful when dealing with reflective PE injection techniques Triage-Collection w/ MAGNET Response (Optional) Collects Running Process/Module Information w/ MAGNET Response Checks for Encrypted Volumes w/ MAGNET Encrypted Disk Detector (EDD) Collects BitLocker Recovery Key Checks for installed Endpoint Security Tools (AntiVirus and EDR) Enumerates all necessary information from the target host to enrich your DFIR workflow Creates a password-protected Secure Archive Container (PW: IncidentResponse) [!TIP] Automated Forensic Analysis of Windows Memory Dumps and corresponding Pagefiles w/ MemProcFS-Analyzer First Public Release MAGNET Talks - Frankfurt, Germany (July 27, 2022) Presentation Title: Modern Digital Forensics and Incident Response Techniques https://www.magnetforens","default_branch":null,"files":null,"tree":[],"storefront":"/r/LETHAL-FORENSICS","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/LETHAL-FORENSICS/Collect-MemoryDump/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}