官术网_书友最值得收藏!

There is more...

If you are planning to use Volatility for memory forensic analysis (and we highly recommend it, because it is the most powerful tool, with lots of plugins, and also it is free and open source), it's very important to choose the right profile. To do this, you will need to know the system type, operating system version, and build number. As you have already learned from the previous recipes, the imageinfo plugin can help you with this task if this information wasn't properly documented during the acquisition stage.

Table 2.1 contains information about profiles added to the most recent version of the Volatility Framework at the time of writing.

Table 2.1. Volatility 2.6 profiles list

Also, it's important to note that on all x64 Windows 8/2012 (and later), the KDBG (which contains a list of the running processes and loaded kernel modules) is encrypted by default, so you should use the virtual address of KdCopyDataBlock. Both addresses can be collected with the kdbgscan Volatility plugin.

主站蜘蛛池模板: 清水县| 万荣县| 阜新市| 波密县| 杂多县| 龙门县| 湘潭市| 金寨县| 乾安县| 平乐县| 金坛市| 天峻县| 凉城县| 新化县| 交口县| 新源县| 邵武市| 六枝特区| 祁门县| 冷水江市| 象山县| 黔西县| 海兴县| 永吉县| 龙井市| 拉孜县| 新建县| 丰城市| 信阳市| 府谷县| 敦化市| 徐水县| 孟连| 巴南区| 永善县| 西盟| 峨边| 永靖县| 祁连县| 鹤山市| 保亭|