infoTECH Feature

March 27, 2013

Belkasoft RAM Capturer Helps Acquire Content from Computers' Volatile Memory

Belkasoft unveiled a kernel-mode forensic tool, Belkasoft RAM (News - Alert) Capturer, that can capture the content of a computer’s volatile memory.

Forensic specialists will be able to take snapshots of the computer’s volatile memory or memory dumps even in the presence of an anti-dumping protection solution. Generally applications protect their memory sets against dumping. The use of improper tools in such cases will destroy important evidence necessitating an optimized tool.

Belkasoft’s free memory dumping tool for digital forensics features a kernel-mode of operation to capture the content of the computer’s volatile memory. The kernel-mode driver can successfully acquire volatile memory sets of applications including chats occurring in Karos and other MMORPG games.

Officials explained that this tool will work on all computers that run current and legacy versions of Windows. The solution also includes 32-bit and 64-bit kernel-mode drivers.

Most applications such as multi-player online games, malware, custom and commercial products come with memory sets that are protected against dumping with active anti-debugging systems.

In protected applications an attempt to read a protected memory area will retrieve wasteful data or zeroes instead of the actual information. Also an anti-debug system can thwart attempts to access information by destroying affected information or causing a kernel mode failure. This will lock up the computer and stop further analysis.

Most free memory dumping tools such as AccessData FTK Imager or PMDump can only run in user mode. However, Belkasoft RAM Capturer serves as an optimized free forensic tool which will help acquire the content of the computer’s volatile memory. It leverages a kernel-mode driver which bypasses all currently available active anti-dumping protection systems such as nProtect GameGuard.

In January 2012, Belkasoft updated its flagship forensic product, Belkasoft Evidence Center 2013, to version 5.2, greatly reducing the time required to collect digital evidence from larger hard drives.

The new release introduces a brand-new core engine, bringing much greater performance to users of last-generation multi-core CPU’s. Belkasoft strives to increase the efficiency of its product, further enhancing the efficiency of forensic investigations and simplifying the process of obtaining digital evidence.




Edited by Brooke Neuman
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers