Skip to content

Latest commit

 

History

History
18 lines (14 loc) · 418 Bytes

volatility.md

File metadata and controls

18 lines (14 loc) · 418 Bytes

Source

https://github.com/volatilityfoundation/volatility

Determine profile (windows, mac, linux) based on KDBG search

volatility -f <file>.vmem imageinfo

List active processes (use psscan for terminated processes and pstree fot parent-child tree)

volatility -f <file>.vmem pslist

Dumpt process to file

volatility -f <file>.vmem procdump --dump-dir <output> -p <processId>