Memory forensics

Volatility

An advanced memory forensics framework GitHub - volatilityfoundation/volatility
1
apt install volatility volatility-tools
Copied!
1
volatility -f <memory-dump-file> imageinfo
2
volatility -f <memory-dump-file> --profile Win2020R2x64 clipboard
3
volatility -f <memory-dump-file> --profile Win2020R2x64 pstree
4
volatility -f <memory-dump-file> --profile Win2020R2x64 hashdump
Copied!
Copy link
Edit on GitHub