[tags]windows,memory[/tags]
[short_descr]The Windows memory acquisition tool.[/short_descr]
[link] https://github.com/Velocidex/WinPmem [/link]
[long_descr]
WinPmem is a physical memory acquisition tool with the following features:
Open source
Support for Win7 - Win 10, x86 + x64. The WDK7600 might be used to include WinXP support. As default, the provided WinPmem executables will be compiled with WDK10, supporting Win7 - Win10, and featuring more modern code.
Three independent reading methods, with two methods to create a complete memory dump. One method should always work even when faced with kernel mode rootkits.
[tags]windows,memory[/tags] [short_descr]The Windows memory acquisition tool.[/short_descr] [link] https://github.com/Velocidex/WinPmem [/link] [long_descr] WinPmem is a physical memory acquisition tool with the following features: