Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 31 volatility -f memdump.mem imageinfo
- 32 volatility -f memdump.mem imageinfo
- 33 volatility -f memdump.mem --profile Win7SP1x64 pslist
- 34 volatility -f memdump.mem --profile Win7SP1x64 pslist
- 35 volatility -f memdump.mem --profile Win7SP1x64 pstree
- 36 volatility -f memdump.mem --profile Win7SP1x64 psxview
- 37 volatility -f memdump.mem --profile Win7SP1x64 dlllist -p 1900
- 38 volatility -f memdump.mem --profile Win7SP1x64 ldrmodules -p 1900
- 39 volatility -f memdump.mem --profile Win7SP1x64 handles -p 1900
- 40 volatility -f memdump.mem --profile Win7SP1x64 mutantscan -p 1900
- 41 volatility -f memdump.mem --profile Win7SP1x64 mutant -p 1900
- 42 volatility -f memdump.mem --profile Win7SP1x64 mutant
- 43 volatility -f memdump.mem --profile Win7SP1x64 mutants
- 44 volatility -f memdump.mem --profile Win7SP1x64 mutantscan
- 45 volatility -f memdump.mem --profile Win7SP1x64 hivedump
- 46 volatility -f memdump.mem --profile Win7SP1x64 hivelist
- 47 volatility -f memdump.mem --profile Win7SP1x64 hashdump -y 0xfffff8a000024010 -s 0xfffff8a001b5e410
- 48 volatility -f memdump.mem --profile Win7SP1x64 netscan
- 49 volatility -f memdump.mem --profile Win7SP1x64 consoles
- 50 volatility -f memdump.mem --profile Win7SP1x64 consoles
- 51 volatility -f memdump.mem --profile Win7SP1x64 cmdscan
- 52 volatility -f memdump.mem --profile Win7SP1x64 cmdscans
- 53* volatility -
- 54 volatility -f memdump.mem --profile Win7SP1x64 consoles
- 55 volatility -f memdump.mem --profile=Win7SP1x64 consoles
- 56 volatility -f memdump.mem --profile=Win7SP1x64 cmdscan
- 57 volatility -f memdump.mem --profile=Win7SP1x64 pslist
- 58 volatility -f memdump.mem --profile=Win7SP1x64 memdump -D ./ -p 1368
- 59 ll
- 60 strings 1368.dmp
- 61 volatility -f memdump.mem --profile=Win7SP1x64 procmemdump -D ./ -p 1368
- 62 volatility -f memdump.mem --profile=Win7SP1x64 procdump -D ./ -p 1368
- 63 file executable.1368.exe
- 64 volatility -f memdump.mem --profile=Win7SP1x64 pslist
- 65 volatility -f memdump.mem --profile=Win7SP1x64 iehistory
- 66 volatility -f memdump.mem --profile=Win7SP1x64 malfind
- 67 history
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement