Memory Analysis

VMEM dump

Use volatility to get some info about the memory dump

circle-info

Depending if you are using Volatility2 or Volatility3, the commands below might differ but the methodology stays pretty much the same.

circle-exclamation
python3 vol.py imageinfo -f Snapshot.vmem

Depending on the output, you might be able to enumerate further.

Last updated

Was this helpful?