Eccouncil 212-89 Exam - Topic 3 Question 55 Discussion
John is performing memory dump analysis in order to find out the traces of malware.He has employed volatility tool in order to achieve his objective.Which of the following volatility framework commands he will use in order to analyze running process from the memory dump?
B) python vol.py pslist --profile=Win2008SP1x86 --f /root/Desktop/memdump.mem
A) python vol.py svcscan --profile=Win2008SP1x86 --f /root/Desktop/memdump.mem | more
C) python vol.py hivelist --profile=Win2008SP1x86 --f /root/Desktop/memdump.mem
D) python vol.py imageinfo -f /root/Desktop/memdump.mem
Stevie
9 months agoDenae
9 months agoLea
10 months agoTracie
10 months agoAliza
10 months agoCyril
10 months agoZona
11 months agoTresa
11 months agoJaime
11 months agoCandida
11 months agoMicaela
11 months agoEladia
11 months agoLeila
11 months agoLevi
11 months agoLeonor
11 months agoKara
11 months agoQuentin
2 years agoCharolette
2 years agoSalome
2 years agoPeter
2 years agoQuentin
2 years agoSalome
2 years ago