官术网_书友最值得收藏!

Getting ready

The Volatility Framework is an open source toolkit, so it's cross-platform, which means that you can use any operating system family you want - Windows, Linux, or mac OS. Of course, you can build these tools from source, but there are also so-called standalone executables for all the operating systems mentioned. As this cookbook is about forensic examination of Windows OS and the memory dump, what we are going to analyze is collected from Windows 10, and we are going to use the Windows Standalone Executable.

At the time of writing, the most recent version of Volatility is 2.6. With this version, support for Windows 10 (including 14393.447) improved, also support for Windows Server 2016, mac OS Sierra 10.12, and Linux with KASLR kernels was added.

To download the collection of tools, go to the Volatility Framework website and use the Releases tab to choose the most recent version, in our case 2.6. Now, all you need is to unzip volatility_2.6_win64_standalone.zip which you've just downloaded, and you are ready to go.

主站蜘蛛池模板: 扎兰屯市| 康保县| 社旗县| 双流县| 许昌县| 河南省| 东莞市| 思茅市| 邻水| 仪陇县| 米林县| 班戈县| 洱源县| 石狮市| 佛学| 拉萨市| 阜南县| 安西县| 库尔勒市| 米泉市| 桂东县| 桐乡市| 灵武市| 安岳县| 达尔| 萍乡市| 岳阳县| 宝应县| 柳州市| 镇远县| 革吉县| 武强县| 苏州市| 博爱县| 忻州市| 华池县| 武定县| 改则县| 梅州市| 三台县| 肇庆市|