Volatility
Memory forensics framework
ΠΡΠ½ΠΎΠ²Π½ΡΠ΅ ΠΊΠΎΠΌΠ°Π½Π΄Ρ (Π² ΠΏΠΎΡΡΠ΄ΠΊΠ΅ ΠΏΠΎΡΠ»Π΅Π΄ΠΎΠ²Π°ΡΠ΅Π»ΡΠ½ΠΎΡΡΠΈ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΡ ΠΈΡ )
imageinfo - ΠΎΠΏΡΠ΅Π΄Π΅Π»ΠΈΡΡ ΠΏΡΠΎΡΠΈΠ»Ρ
pstree - Π΄Π΅ΡΠ΅Π²ΠΎ ΠΏΡΠΎΡΠ΅ΡΡΠΎΠ²
cmdline - Π°ΡΠ³ΡΠΌΠ΅Π½ΡΡ ΠΏΡΠΎΡΠ΅ΡΡΠΎΠ²
procdump - ΡΠ΄Π°ΠΌΠΏΠΈΡΡ Π΅Ρ Π΅ΡΠ½ΠΈΠΊ
netscan - ΡΠΎΠ΅Π΄ΠΈΠ½Π΅Π½ΠΈΡ
filescan - Π»ΠΈΡΡΠΈΡΡ ΡΠ°ΠΉΠ»Ρ
dumpfiles - Π΄ΠΎΡΡΠ°Π²Π°ΡΡ ΡΠ°ΠΉΠ»Ρ
bioskbd - ΠΊΠ»Π°Π²ΠΈΠ°ΡΡΡΠ°
clipboard - Π±ΡΡΠ΅Ρ
consoles - ΠΈΡΡΠΎΡΠΈΡ ΠΊΠΎΠΌΠ°Π½Π΄ Π² ΠΊΠΎΠ½ΡΠΎΠ»ΠΈ
hashdump - Ρ Π΅ΡΠΈ ΠΏΠ°ΡΠΎΠ»Π΅ΠΉ
iehistory - ΠΈΡΡΠΎΡΠΈΡ IE
screenshot - ΡΠΊΡΠΈΠ½ΡΠΎΡ
truecryptmaster
truecryptpassphrase
truecryptsummary
printkey - ΠΊΠ»ΡΡΠΈ ΡΠ΅Π΅ΡΡΡΠ°
volatility -f MyPC-a44c4946.vmem imageinfo
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 pstree
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 procdump --dump-dir .
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 cmdline
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 filescan
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 filescan | grep resume-vm-default.bat
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 dumpfiles -Q 0x000000001df3f1b8 --dump-dir .
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 netscan
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 bioskbd
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 clipboard
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 consoles
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 screenshot --dump-dir .
volatility -f MyPC-a44c4946.vmem --profile=Win7SP1x86_23418 truecryptsummary
Last updated