-
Notifications
You must be signed in to change notification settings - Fork 167
Device_DumpIt
ufrisk edited this page Mar 2, 2023
·
5 revisions
The LeechCore library supports reading live memory by using Comae DumpIt.
Facts in short:
- Is supported on 32-bit and 64-bit Windows.
- Acquires memory in read-only mode.
- Acquired memory is assumed to be volatile.
- Have additional requirements.
The LeechCore process must be started from DumpIt in elevated administrator mode for DumpIt to be able to capture live memory.
LeechCore API:
Please specify the acquisition device type in LC_CONFIG.szDevice when calling LcCreate. The acquisition device type is dumpit.
PCILeech / MemProcFS:
Please specify the device type in the -device option or start from DumpIt directly
Examples:
-device dumpit -remote rpc://<spn>:<somehost>
DumpIt.exe /LIVEKD /A MemProcFS.exe
Depends on DumpIt.exe. Please download the latest version of DumpIt from Magnet Forensics.