Practical No.
3
Aim: Analyze the memory dump of a running computer system.
Extract volatile data, such as open processes, network connections, and
registry information.
Name: Moazzam Mulla
Class: TYCS(A)
Roll No: 27
Subject: Cyber Forensics
Sign:
Name: Moazzam Mulla
Class: TYCS(A)
Roll No: 27
Practical No. 3
Aim: Analyze the memory dump of a running computer system.
Extract volatile data, such as open processes, network connections, and
registry information.
Open Process:-
Go to Sysinternal Suite ProcMonRight Click on it and Open As Administrator.
Cyber Forensics
Name: Moazzam Mulla
Class: TYCS(A)
Roll No: 27
Network Connections
Go to SysinternalSuite TCPview
Cyber Forensics
Name: Moazzam Mulla
Class: TYCS(A)
Roll No: 27
Registry Information
Click on Search Bar on the Taskbar Type Regedit Click on Registry Editor
View the desired registries to be analyzed
Cyber Forensics
Name: Moazzam Mulla
Class: TYCS(A)
Roll No: 27
Cyber Forensics