赞
踩
Volatility
是一款开源的内存取证分析工具,支持Windows
,Linux
,MaC
,Android
等多类型操作系统系统的内存取证方式。该工具是由python
开发的,目前支持python2
、python3
环境。
GitHub - volatilityfoundation/volatility: An advanced memory forensics framework
https://github.com/volatilityfoundation/volatility3
pip3 install -r requirements-minimal.txt
python3 setup.py build
python3 setup.py install
pip3 install -r requirements.txt
vol.py -f E:\检材二内存\memory windows.info
vol.py -f E:\检材二内存\memory windows.pslist
vol.py -f E:\检材二内存\memory windows.pstree
vol.py -f E:\检材二内存\memory windows.pslist --pid 540 --dump
vol.py -f E:\检材二内存\memory windows.filescan
进程号(PID),进程名称(Process)和参数(Args)三列
vol.py -f E:\检材二内存\memory windows.cmdline.CmdLine
8、查看动态链接库(windows.dlllist)
vol.py -f E:\检材二内存\memory windows.dlllist
9、查看账号信息(windows.hashdump)
10、注册表数据(windows.registry.hivelist)
11、网络连接状态(windows.netscan.NetScan)
12、服务运行状态(windows.svcscan)
13、进程环境变量(windows.envars)
14、进程缓存的文件(windows.dumpfiles)
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。