Reminiscent
vol.py -f flounder-pc-memdump.elf imageinfo
Suggested Profile(s) : Win7SP1x64, Win7SP0x64, Win2008R2SP0x64, Win2008R2SP1x64_23418, Win2008R2SP1x64, Win7SP1x64_23418
AS Layer1 : WindowsAMD64PagedMemory (Kernel AS)
AS Layer2 : VirtualBoxCoreDumpElf64 (Unnamed AS)
AS Layer3 : FileAddressSpace (/home/infosec/dumps/mem_dumps/01/flounder-pc-memdump.elf)
PAE type : No PAE
DTB : 0x187000L
KDBG : 0xf800027fe0a0L
Number of Processors : 2
Image Type (Service Pack) : 1
KPCR for CPU 0 : 0xfffff800027ffd00L
KPCR for CPU 1 : 0xfffff880009eb000L
KUSER_SHARED_DATA : 0xfffff78000000000L
Image date and time : 2017-10-04 18:07:30 UTC+0000
Image local date and time : 2017-10-04 11:07:30 -0700remnux@remnux:~/ctf/memoryctf/reminiscent$ vol.py --profile=Win7SP1x64 -f flounder-pc-memdump.elf pstree
Name Pid PPid Thds Hnds Time
-------------------------------------------------- ------ ------ ------ ------ ----
0xfffffa800169bb30:csrss.exe 348 328 9 416 2017-10-04 18:04:29 UTC+0000
0xfffffa8001f63b30:wininit.exe 376 328 3 77 2017-10-04 18:04:29 UTC+0000
. 0xfffffa8001ff2b30:lsass.exe 492 376 8 590 2017-10-04 18:04:30 UTC+0000
. 0xfffffa8001fcdb30:services.exe 476 376 11 201 2017-10-04 18:04:29 UTC+0000
.. 0xfffffa8002204960:svchost.exe 384 476 17 386 2017-10-04 18:04:30 UTC+0000
... 0xfffffa8001efa500:csrss.exe 396 384 9 283 2017-10-04 18:04:29 UTC+0000
.... 0xfffffa8000e90060:conhost.exe 2772 396 2 55 2017-10-04 18:06:58 UTC+0000
... 0xfffffa8001f966d0:winlogon.exe 432 384 4 112 2017-10-04 18:04:29 UTC+0000
.. 0xfffffa80021044a0:svchost.exe 792 476 21 443 2017-10-04 18:04:30 UTC+0000
.. 0xfffffa800209bb30:VBoxService.ex 664 476 12 118 2017-10-04 18:04:30 UTC+0000
.. 0xfffffa800217cb30:svchost.exe 900 476 41 977 2017-10-04 18:04:30 UTC+0000
.. 0xfffffa8002294b30:spoolsv.exe 1052 476 13 277 2017-10-04 18:04:31 UTC+0000
.. 0xfffffa8002122060:sppsvc.exe 1840 476 4 145 2017-10-04 18:04:37 UTC+0000
.. 0xfffffa80021b4060:SearchIndexer. 1704 476 16 734 2017-10-04 18:04:47 UTC+0000
... 0xfffffa80023ed550:SearchFilterHo 812 1704 4 92 2017-10-04 18:04:48 UTC+0000
... 0xfffffa80024f4b30:SearchProtocol 1960 1704 6 311 2017-10-04 18:04:48 UTC+0000
.. 0xfffffa80021ccb30:svchost.exe 988 476 13 286 2017-10-04 18:04:30 UTC+0000
.. 0xfffffa8002390620:svchost.exe 1196 476 28 333 2017-10-04 18:04:31 UTC+0000
.. 0xfffffa800096eb30:wmpnetwk.exe 2248 476 18 489 2017-10-04 18:06:33 UTC+0000
.. 0xfffffa8002245060:taskhost.exe 1720 476 8 148 2017-10-04 18:04:36 UTC+0000
.. 0xfffffa80022bbb30:svchost.exe 1092 476 19 321 2017-10-04 18:04:31 UTC+0000
.. 0xfffffa8000945060:svchost.exe 2120 476 12 335 2017-10-04 18:06:32 UTC+0000
.. 0xfffffa8002001b30:svchost.exe 600 476 12 360 2017-10-04 18:04:30 UTC+0000
... 0xfffffa8000801b30:WmiPrvSE.exe 2924 600 10 204 2017-10-04 18:06:26 UTC+0000
... 0xfffffa8000930b30:WmiPrvSE.exe 592 600 9 127 2017-10-04 18:06:35 UTC+0000
.. 0xfffffa8002166b30:svchost.exe 868 476 21 429 2017-10-04 18:04:30 UTC+0000
... 0xfffffa80022c8060:dwm.exe 2020 868 4 72 2017-10-04 18:04:41 UTC+0000
.. 0xfffffa80020b5b30:svchost.exe 728 476 7 270 2017-10-04 18:04:30 UTC+0000
. 0xfffffa8001fffb30:lsm.exe 500 376 11 150 2017-10-04 18:04:30 UTC+0000
0xfffffa80006b7040:System 4 0 83 477 2017-10-04 18:04:27 UTC+0000
. 0xfffffa8001a63b30:smss.exe 272 4 2 30 2017-10-04 18:04:27 UTC+0000
0xfffffa80020bb630:explorer.exe 2044 2012 36 926 2017-10-04 18:04:41 UTC+0000
. 0xfffffa80022622e0:VBoxTray.exe 1476 2044 13 146 2017-10-04 18:04:42 UTC+0000
. 0xfffffa80007e0b30:thunderbird.ex 2812 2044 50 534 2017-10-04 18:06:24 UTC+0000
. 0xfffffa800224e060:powershell.exe 496 2044 12 300 2017-10-04 18:06:58 UTC+0000
.. 0xfffffa8000839060:powershell.exe 2752 496 20 396 2017-10-04 18:07:00 UTC+0000First Method :



Second Method :
WinEVT Logs :

Flag :

Last updated