Published
2022-02-20

How to Cite

Gutiérrez Oquendo, H. (2022). Evaluation of free software tools, for the Windows operating system, in the acquisition of RAM memory evidences. Publicaciones E Investigación, 16(1). https://doi.org/10.22490/25394088.5567
Metrics
Metrics Loading ...

Evaluation of free software tools, for the Windows operating system, in the acquisition of RAM memory evidences.

DOI: https://doi.org/10.22490/25394088.5567
Section
Artículo original
Henry Gutiérrez Oquendo 0000-0002-8300-2014 https://orcid.org/0000-0002-8300-2014

The objective of this article, is to evaluate free software tools of the Windows operating system, for the acquisition of evidence of RAM memory, using the ISO/IEC 25010 standard that defines characteristics and measures of quality of use of a product. The above takes into consideration the technical form for RAM dump analysis and the use of the specific tools DumpIt, FTK Imager, Windows Forensic Toolchest (WFT), OS Forensic and RamCapturer.

In order to guarantee the usefulness of the selected tools, it is contemplated to define, classify, identify, obtain, analyze and interpret results obtained with the Volatility tool, and thus be able to detect which instrument recovers more, the most efficient one that affects the evidence less. The latter is of utmost importance, since a very subtle alteration could change the HASH obtaining large scale problems in a trial.