Digital forensic examiners are investigators who are experts in gathering, recovering, analyzing, and presenting data evidence from computers and other digital media related to computer-based .They might work on cases concerning identity theft, electronic fraud,investigation of material found in digital devices ,electronic evidence, often in relation to cyber crimes.
Launch FTK Imager: Open the FTK Imager application on your computer.
Initiate memory capture: Click on File in the top menu bar, then select Capture Memory.
Configure destination:
Click the browse button (...) next to Destination Path.
Navigate to and select a folder where you want to save the image, preferably an external drive.
Enter a filename for the memory dump (e.g., memdump.mem).
Set options (optional but recommended):
Include pagefile: Check the box to include the pagefile in the capture, which can provide additional data.
Create AD1 file: Check this box to create a single, compressed, and hashed image file that includes the memory dump and pagefile (if selected).
Start the capture: Click the Capture Memory button to begin the process. A progress bar will show the status, and you will need to wait for it to finish.