官术网_书友最值得收藏!

There is more...

If you are planning to use Volatility for memory forensic analysis (and we highly recommend it, because it is the most powerful tool, with lots of plugins, and also it is free and open source), it's very important to choose the right profile. To do this, you will need to know the system type, operating system version, and build number. As you have already learned from the previous recipes, the imageinfo plugin can help you with this task if this information wasn't properly documented during the acquisition stage.

Table 2.1 contains information about profiles added to the most recent version of the Volatility Framework at the time of writing.

Table 2.1. Volatility 2.6 profiles list

Also, it's important to note that on all x64 Windows 8/2012 (and later), the KDBG (which contains a list of the running processes and loaded kernel modules) is encrypted by default, so you should use the virtual address of KdCopyDataBlock. Both addresses can be collected with the kdbgscan Volatility plugin.

主站蜘蛛池模板: 治县。| 宿松县| 潮州市| 申扎县| 南充市| 常山县| 西藏| 许昌县| 庄河市| 秦安县| 玉环县| 清新县| 临漳县| 大冶市| 肃北| 霸州市| 平昌县| 瓮安县| 芜湖市| 常州市| 绥中县| 巨野县| 井研县| 吴旗县| 固原市| 康保县| 饶河县| 保德县| 陈巴尔虎旗| 三台县| 广元市| 焦作市| 土默特左旗| 凌海市| 行唐县| 陵水| 巫溪县| 泸溪县| 高密市| 广灵县| 隆子县|