volatility -f [image] --profile=[profile] [plugin]
volatility -f xxx.vmem imageinfo
volatility -f 1.vmem --profile=Win7SP1x64 hashdump
volatility -f 1.vmem --profile=Win7SP1x64 pslist
volatility -f 1.vmem --profile=Win7SP1x64 svcscan
volatility -f 1.vmem --profile=Win7SP1x64 iehistory
volatility -f 1.vmem --profile=Win7SP1x64 netscan
volatility -f 1.vmem --profile=Win7SP1x64 cmdscan
volatility -f 1.vmem --profile=Win7SP1x64 filescan
volatility -f 1.vmem --profile=Win7SP1x64 dumpfiles -Q 0xxxxxxxx -D ./
volatility -f 1.vmem --profile=Win7SP1x64 notepad
volatility -f 1.vmem --profile=Win7SP1x64 memdump -p xxx --dump-dir=./
volatility -f 1.vmem --profile=Win7SP1x64 screenshot --dump-dir=./
volatility -f 1.vmem --profile=Win7SP1x64 hivelist
volatility -f 1.vmem --profile=Win7SP1x64 hivedump -o 0xfffff8a001032410
volatility -f 1.vmem --profile=Win7SP1x64 printkey -K "xxxxxxx"
volatility -f 1.vmem --profile=Win7SP1x64 userassist
volatility -f 1.vmem --profile=Win7SP1x64 timeliner
volatility -f easy_dump.img imageinfo
#脚本文件
import matplotlib.pyplot as plt
import numpy as npx = []
y = []
with open('hint.txt','r') as f:
datas = f.readlines()
for data in datas:
arr = data.split(' ')
x.append(int(arr[0]))
y.append(int(arr[1]))plt.plot(x,y,'ks',ms=1)
plt.show()
E
N
D
本文作者:TideSec
本文为安全脉搏专栏作者发布,转载请注明:https://www.secpulse.com/archives/197037.html