A high level overview to perform live memory captures and analysis:
- capture memory via moonsol’s win32dd
- parse memory snapshot with mandiant’s memoryze
- analyze results via audit viewer
- or analyze using the volatility framework — neatly packaged in SAN’S Sift Workstation


