Memory Analysis - Volatility3
Memory Analysis using Volatility3
Theory
Volatility3 Commands
OS Information
vol.py -f “/path/to/file” windows.infoProcess Information
pslist
vol.py -f “/path/to/file” windows.pslist
vol.py -f “/path/to/file” windows.psscan
vol.py -f “/path/to/file” windows.pstreecmdline
DLLs
Network Information
netscan
Registry
hivelist
Files
Filescan
Filedump
Miscellaneous
Yarascan
REFERENCES
Last updated