The invention provides a remote evidence taking
system based on physical
memory analysis. The remote evidence taking
system is characterized by comprising a
client and a
server, wherein a physical memory of the
client is mirrored and stored locally, and a
mirror image file is subjected to hash value calculation; the
mirror image file is analyzed by calling a physical
memory analysis line program, and an analysis result and the
mirror image file are sent to the
server together; the
server is used for monitoring the
client; if a client connection request is provided, a client fixing character string is sent, and the physical memory mirror image file and the corresponding mirror image file analysis result of the client are mainly collected; the server collects multiple threads and can simultaneously collect the physical memory mirror image files of multiple clients and
memory analysis result information and store the memory analysis results into a
database; on the other hand, the server is connected with a
remote control terminal to mainly send log information of the client to the
remote control terminal; retrieval information meeting retrieval conditions are searched from the
database according to the conditions of the
remote control terminal.