![]() ![]() Portable kernel-mode Live RAM Capturer available free of charge to acquire system memory sets protected with active anti-dedugging systems.Handy built-int regedit-like viewer shows even badly damaged or corrupted files, particularly those resulting from carving of registries from unallocated space Automatically locates, parses and carves registry hives, extracting many types of valuable evidence.in both textual and graphical representation Offers an aggregated view of all user activities regardless of data source including all supported email clients, instant messengers, social networks etc.Sophisticated BelkaCarving algorithm carefully reconstructs fragmented chunks into contiguous pieces of information, allowing the tool to extract broken pieces such as databases, recently viewed images, documents and other types of data that no other tool can access.Enhanced Live RAM Analysis with BelkaCarving:.Recovers corrupted and incomplete SQLite databases, restores deleted records and cleared history files. ![]() Native SQLite parsing with freelist support and built-in viewer:.More on Live memory (RAM) analysis and page/hibernation file analysis Recovers deleted and destroyed evidence as well as evidence stored in memory dumps, page and hibernation files.Allows unlimited sharing of discovered evidence at no extra charge. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |