The Full Memory script requests full memory data from host endpoints from the beginning of physical memory and uses the memory‑acquisition audit. This script acquires the full memory of the system. You can request this script for Windows host endpoints only.
Note
Full Memory script support is not provided for macOS or Linux host endpoints.
You cannot copy, edit, reset, import, or delete the Full Memory script or use this script in data acquisition scripts you create.
Caution
Full memory data acquisitions can return more information than expected and cause performance and storage problems. Trellix recommends that you limit the scope of this script using the Acquire Full Memory dialog box.
.png)
The following table describes the fields in this dialog box. None of these fields are required.
Field | Description |
|---|---|
Offset | Specify the offset, in bytes, from the beginning of physical memory from which full memory data should be acquired. |
Size | Specify the size, in bytes, of full memory data to acquire. |
Comment | Enter any details about your specific data acquisition request and enter the reason you want to acquire the file. |
NoteThe Full Memory dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains. | |
Requesting full memory data
Select Hosts in the Endpoint Security (HX) Web UI.
Select a host.
Note
If you select multiple hosts, the Full Memory data acquisition option is not available. This script can only be requested when a single host is selected.
From the Actions menu, select Full Memory and click Go. Alternatively, you can select Full Memory from the Acquire menu on a host details page.
Click Go to access the Acquire Full Memory dialog box.
In the Offset field, enter the disk offset (in bytes) from the beginning of the physical memory.
Note
If you leave the Offset and Size values blank, you will acquire all process memory data.
In the Size field, enter the size (in bytes) of the full memory data you want to acquire.
In the Comment field, enter the reason you want to acquire the file and any details about the data acquisition request that you want to track.
Click Acquire.
A downloadable .zip file is produced from a Full Memory acquisition request. Extract the contents of the zip file using any unzipping tool. Locate and convert the file with the largest file size to image format (*.img). Then open the image format file with any open source forensic tool (such as Forensic Toolkit (FTK) or the Volatility Foundation's memory forensics framework).
Full Memory data can be requested as a regular data acquisition. See Requesting a data acquisition.