Memory Acquisition
Live System Memory acquisition:
Pagefile.sys
Dead System Memory Acquisition:
# Hibernation File:
%SystemDrive%\hiberfil.sys
# Page and Swap files:
%SystemDrive%\PageFile.sys
%SystemDrive%\SwapFile.sys #(Win8+/2012+)
### Reg Key
SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
# Kernel memory dumps:
%SystemRoot%\MEMORY.DMP
### Registry key to set:
SYSTEM\CurrentControlSet\Control\CrashControlHibernation File:
Last updated