Full Memory script

Prev Next

The Full Memory script requests full memory data from host endpoints from the beginning of physical memory and uses the memory‑acquisition audit. This script acquires the full memory of the system. You can request this script for Windows host endpoints only.

Note

Full Memory script support is not provided for macOS or Linux host endpoints.

You cannot copy, edit, reset, import, or delete the Full Memory script or use this script in data acquisition scripts you create.

Caution

Full memory data acquisitions can return more information than expected and cause performance and storage problems. Trellix recommends that you limit the scope of this script using the Acquire Full Memory dialog box.

HX_SSType_FullMemory_scap.png

The following table describes the fields in this dialog box. None of these fields are required.

Field

Description

Offset

Specify the offset, in bytes, from the beginning of physical memory from which full memory data should be acquired.

Size

Specify the size, in bytes, of full memory data to acquire.

Comment

Enter any details about your specific data acquisition request and enter the reason you want to acquire the file.

Note

The Full Memory dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains.

Requesting full memory data

To request full memory data using the Web UI:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select a host.

    Note

    If you select multiple hosts, the Full Memory data acquisition option is not available. This script can only be requested when a single host is selected.

  3. From the Actions menu, select Full Memory and click Go. Alternatively, you can select Full Memory from the Acquire menu on a host details page.

  4. Click Go to access the Acquire Full Memory dialog box.

  5. In the Offset field, enter the disk offset (in bytes) from the beginning of the physical memory.

    Note

    If you leave the Offset and Size values blank, you will acquire all process memory data.

  6. In the Size field, enter the size (in bytes) of the full memory data you want to acquire.

  7. In the Comment field, enter the reason you want to acquire the file and any details about the data acquisition request that you want to track.

  8. Click Acquire.

A downloadable .zip file is produced from a Full Memory acquisition request. Extract the contents of the zip file using any unzipping tool. Locate and convert the file with the largest file size to image format (*.img). Then open the image format file with any open source forensic tool (such as Forensic Toolkit (FTK) or the Volatility Foundation's memory forensics framework).

Full Memory data can be requested as a regular data acquisition. See Requesting a data acquisition.