官术网_书友最值得收藏!

Getting ready

The Volatility Framework is an open source toolkit, so it's cross-platform, which means that you can use any operating system family you want - Windows, Linux, or mac OS. Of course, you can build these tools from source, but there are also so-called standalone executables for all the operating systems mentioned. As this cookbook is about forensic examination of Windows OS and the memory dump, what we are going to analyze is collected from Windows 10, and we are going to use the Windows Standalone Executable.

At the time of writing, the most recent version of Volatility is 2.6. With this version, support for Windows 10 (including 14393.447) improved, also support for Windows Server 2016, mac OS Sierra 10.12, and Linux with KASLR kernels was added.

To download the collection of tools, go to the Volatility Framework website and use the Releases tab to choose the most recent version, in our case 2.6. Now, all you need is to unzip volatility_2.6_win64_standalone.zip which you've just downloaded, and you are ready to go.

主站蜘蛛池模板: 卢龙县| 日照市| 乌兰察布市| 乌兰察布市| 昭通市| 石泉县| 当涂县| 西和县| 博爱县| 临江市| 唐山市| 安乡县| 台湾省| 新邵县| 淳化县| 永康市| 凤凰县| 玉屏| 灵寿县| 新平| 东丽区| 永丰县| 韶关市| 德江县| 新兴县| 寻甸| 永登县| 满城县| 漳浦县| 德昌县| 如东县| 临汾市| 玛纳斯县| 潞城市| 安多县| 广州市| 新乡县| 信丰县| 潞西市| 潢川县| 房产|