BUUCTF V&N-misc内存取证
分析镜像: volatility -f mem.raw imageinfo 查看进程: volatility -f mem.raw --profile=Win7SP1x86_23418 pslist 列出我认为的可疑的进程: explorer.exe TrueCrypt.exe notepad.exe iexplore.exe mspaint.exe DumpIt.exe dump记事本、画图进程: volatility -f mem.raw --profile=Win7SP1x86_23418 memdump -p 3552 --dump-dir=./ volatility -f mem.raw --profile=Win7SP1x86_23418 memdump -p 2648 --dump-dir=./ 2648.bmp的后缀改为data 查看IE浏览器历史: volatility -f mem.raw --profile=Win7SP1x86_23418 iehistory <a href="https://sm.ms/image/AQ3lagDhWHCUnYK" target="_blank"><img src="https://i.loli.net/2020/03/01/AQ3lagDhWHCUnYK.png" width="60%" height="60%"></a>