官术网_书友最值得收藏!

Getting ready

The Volatility Framework is an open source toolkit, so it's cross-platform, which means that you can use any operating system family you want - Windows, Linux, or mac OS. Of course, you can build these tools from source, but there are also so-called standalone executables for all the operating systems mentioned. As this cookbook is about forensic examination of Windows OS and the memory dump, what we are going to analyze is collected from Windows 10, and we are going to use the Windows Standalone Executable.

At the time of writing, the most recent version of Volatility is 2.6. With this version, support for Windows 10 (including 14393.447) improved, also support for Windows Server 2016, mac OS Sierra 10.12, and Linux with KASLR kernels was added.

To download the collection of tools, go to the Volatility Framework website and use the Releases tab to choose the most recent version, in our case 2.6. Now, all you need is to unzip volatility_2.6_win64_standalone.zip which you've just downloaded, and you are ready to go.

主站蜘蛛池模板: 崇礼县| 体育| 革吉县| 禹州市| 大石桥市| 永川市| 宣武区| 吴堡县| 益阳市| 襄城县| 德州市| 瑞丽市| 寻甸| 祁门县| 灵石县| 乌鲁木齐市| 吉安县| 衢州市| 习水县| 平陆县| 萨迦县| 洛宁县| 于都县| 乌拉特前旗| 元朗区| 青铜峡市| 仪陇县| 全州县| 北票市| 永川市| 吴桥县| 荣昌县| 肃宁县| 白城市| 调兵山市| 定边县| 法库县| 青川县| 华亭县| 司法| 济宁市|