
上QQ阅读APP看书,第一时间看更新
Windows memory acquisition with DumpIt
DumpIt is a free memory imaging tool from Comae Memory Toolkit. It's a fusion of Win32dd and Win64dd in one executable. It's extremely easy to use: even a non-technical person can use it in emergency situations. DumpIt supports all modern Windows versions, from XP to 10, both 32 and 64-bit. Also, the tool has a very important feature: it displays the Directory Table Base and the address of the debugging data structures during the acquisition process.