内存取证

python /root/volatility-master/vol.py --file="neicun.vmem" imageinfo

mh74uau8.png

python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 pslist

mh74w1op.png

python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 envars

mh74z1yt.png

python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 cmdscan

mh75wqhx.png

python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 consoles

mh75yqsn.png

python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 cmdline

mh7ba6wp.png

python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 psscan

mh7bd4yq.png

python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 filescan
mh7brs52.png
python /root/volatility-master/vol.py --file="neicun.vmem" --profile=Win7SP1x64 hashdump
mh7bxgur.png

无标签
评论区
头像