Pagefile.sys (Windows)

Pagefile.sys is a hidden system file in Windows used to support virtual memory. When the system’s physical RAM becomes full, less frequently accessed memory pages are moved (paged out) to this file, freeing up RAM for active tasks.

image.png

image.png

Functionality

For DFIR/SOC:

Extracting using FTK Imager

image.png

The output folder shows the files extracted from the pagefile below.

Image showing bulk extractor output