We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
You are on page 1/ 3
EXPERIMENT-08
‘Aim of the Experiment: How to Collect Email Evidence in Victim PC
To collect email evidence from Victim PC the first step is to capture the victim’s
RAM. This can be possible using dumpit tool
This utility is used to generate a physical memory dump of Windows machines. It
works with both x86 (32-bits) and x64 (64-bits) machines. The raw memory dump is
generated in the current directory, only a confirmation question is prompted before
starting. Perfect to deploy the executable on USB keys, for quick incident responses
needs.
Run Dumpit.exe file the raw memory dump will be generated and save to the same
directory
ADumsthDumaitoe
eae eres
pores:
oe
See ee eos
‘The output RAW file will be as follows
ssictesctomen EY studocu
Downloaded by Muhammad Tariq (saaimt @gmaicom
‘This documents
Page | 24Name Date modified
ouput
[& ASEEM-PC-20200217-105827.raw
(TE) bulk etractor6t.ene
Bi dumptere
READMEDt 1
Tat AM
459M
Type
File folder
RAW File
‘Application
Appl
Test Document
‘Then Download bulk extractor viewer from GitHub and install it in your PC. Now open bulk
extractor viewer and click on to generate report.
Now select the dump it image file and select an output folder for the report and click on start
bulk extractor as seen below
Page | 25
Downloaded by Muhammad Tariq (saaim01@gmaicom)‘Now in order to investigate the victim saved information of Email ID Click on email.txt as seen
below
1057365
Page | 26
Tissoamemisasiaetactumen Ey studocu
Downloaded by Muhammad Tariq (saaim1@gmsaicom)