Extract live data from a memory dump


banderas20

New Member
Apr 23, 2019
19
Ratings
7
3
#1
Hi.

I have a Windows memory dump and I am analyzing it with Volatility.

I have seen many interesting processes. However, I would need to get some live data regarding these processes.
Such as linked Paths, opened documents, passwords entered, and so on.

¿How can achieve this?

Many thanks!
 

azuleonyx

Member
Experienced Member
Oct 20, 2018
58
Ratings
46
18
Charlotte, North Carolina Area
cyberfenixtech.blogspot.com
Twitter
https://twitter.com/AzuleOnyx
#2

About us

  • Our community began in 2004. Since this time, we have grown to have over 29,000+ members within the DFIR & Cyber Security community.

    We are happy to announce that this forum is now under new ownership with the goal to once again become the main Digital Forensics Forum on the internet for DFIR, OSINT and Cyber Security.

    If you can think of ways to help us improve, please let us know.

    We pride ourselves on offering unbiased, critical discussion among people of all different backgrounds.

    We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu