• Home
  • Products
  • Training
  • Support
  • About Us
  • Forum
  • Sign In

Memory Viewer

Discover
  • Find files faster
  • Search within files
  • Search for E-mails
  • Recover deleted files
  • Uncover User Activity
  • Collect system information
  • Password recovery
  • Hidden Disk Areas - HPA/DCO
  • Volume Shadow Copy
  • Web Browser
Identify
  • Verify and match files
  • Find misnamed files
  • Compare drive signatures
  • Timeline viewer
  • File viewer
  • Memory viewer
  • Binary String Extraction
  • Email viewer
  • Registry viewer
  • File system browser
  • Raw disk viewer
  • Thumbnail cache viewer
  • SQLite database browser
  • ESE database browser
  • Prefetch viewer
  • $UsnJrnl viewer
  • Plist viewer
  • Event Log Viewer
  • Web Server Log Viewer
Manage
  • Case management
  • Generate reports
  • Storage device management
  • Drive Imaging
  • Cloud Drive Imaging
  • Cloud Account Imaging
  • Rebuild RAID arrays
  • Portability
  • Secure case logging
  • Support

OSForensics™ allows the user to perform memory forensics analysis on a live system or a static memory dump. There are 2 types of memory analysis that can be performed:

  • Live Analysis
  • Static Analysis

When performing 'Live Analysis', the memory details of all processes currently running on the system is displayed in a Task Manager-like view. Unlike non-volatile hard disks which can be analyzed statically, memory contents (RAM) can only be analyzed while the system is live. Furthermore, it is possible that potentially implicating evidence exists only in the system's physical memory, without any traces on the hard disk. This matter is complicated further if the data only exists in memory for a brief period of time.


'Static Analysis' allows an investigator to perform an analysis of a memory snapshot dump that had been taken recently. The results of a static analysis can include the following:

  • List of processes that were running
  • List of suspicious processes
  • Installed drivers
  • Detected Malware

Once a dump has been created it can be used with Volatility Workbench or strings can be extracted from within OSForensics, with pre-set filter lists.


Memory Viewer


Memory Viewer


Memory Viewer

Home
Discover Identify Manage
Contact Us Legal Disclaimer Privacy Policy
Products
OSForensics OSForensics Bootable (USB Flash Drive) Rainbow Tables - 3TB hard disk
Training
Online Training Course Certification Exam - Online Triage Exam - Online Face-to-Face Classes 2026 Events Calendar
Support
Video Demonstrations FAQs and Tutorials OSForensics Forums Australian Head Office North American Branch

Copyright © 2025 PassMark™ Software