当前位置:网站首页>Secondary vocational group network security - memory Forensics
Secondary vocational group network security - memory Forensics
2022-07-04 04:55:00 【Beluga】
volatility -f test2.raw imageinfo
Get image details profile Parameters are important It will be used later

volatility -f test2.raw --profile=Win7SP1x64 hashdump
Get mirrored hash Value and user name After obtaining, you can use john Tools for dictionary decryption Or use ophcrack Crack

If there is mimikatz plug-in unit You can use it directly mimikatz To crack Direct password
The other is lsadump Can come out intermittent password It's not complete
volatility -f test2.raw --profile=Win7SP1x64 netscan Check the network connection

A lot of information will come out here ip According to the open port, we judge that 10.30.21.96 Go to the virtual machine to detect So it is
volatility -f test2.raw --profile=Win7SP1x64 envars | grep USERNAME

You can view the host name , Be careful to remove the back $ Symbol
obtain flag Document ideas :
1. Get the desktop file name , Guess its content
volatility -f test2.raw --profile=Win7SP1x64 filescan | grep Desktop

You can see the files on the desktop But can't read its contents
2. Maybe the desktop opens a notepad Program Use notepad You can see
volatility -f test2.raw --profile=Win7SP1x64 notepad
Mining process ideas :
1. First find the process with abnormal name such as Explore.exe The original system process is explorer.exe
2. In the case of Wei Guo in the previous way, the start time of the monitoring system process Judging from the starting time
3. Anyway, only the port and ip, Find external ip Try one by one
volatility -f test2.raw --profile=Win7SP1x64 netscan/connscan
volatility -f test2.raw --profile=Win7SP1x64 svcscan
volatility -f test2.raw --profile=Win7SP1x64 hivelist
Get browser history
volatility -f test2.raw iehistory
I'll give you one url From the parameters inside, you can see what has been searched
边栏推荐
- 自动化测试selenium基础篇——webdriverAPI
- MySQL indexes and transactions
- Share some of my telecommuting experience
- [cloud native] those lines of code that look awesome but have a very simple principle
- Kivy教程之 自定义字体(教程含源码)
- 【MATLAB】MATLAB 仿真模拟调制系统 — FM 系统
- 【MATLAB】通信信号调制通用函数 — 傅里叶逆变换
- Technology Management - learning / practice
- 【MATLAB】MATLAB 仿真模拟调制系统 — DSB 系统
- Distributed cap theory
猜你喜欢

《Cross-view Transformers for real-time Map-view Semantic Segmentation》论文笔记

Technology Management - learning / practice

6-5 vulnerability exploitation SSH weak password cracking and utilization

C basic (VII) document operation

MySQL indexes and transactions

优秀的测试/开发程序员是怎么修炼的?该往哪走......

MySQL JDBC programming

Intersection traffic priority, illustration of intersection traffic rules

如何构建属于自己的知识引擎?社群开放申请

在代码中使用度量单位,从而生活更美好
随机推荐
20000 words will take you to master multithreading
RPC - grpc simple demo - learn / practice
RAC delete damaged disk group
【MATLAB】MATLAB 仿真 — 模拟调制系统 之 AM 调制过程
网络设备应急响应指南
【MATLAB】MATLAB 仿真 — 低通高斯白噪声
附件三:防守方评分标准.docx
附件六:防守工作简报.docx
Using jsts in esmodule environment
Kivy tutorial custom fonts (tutorial with source code)
【无标题】
简单g++和gdb调试
PostgreSQL 正式超越 MySQL,这家伙也太强了吧!
[go] database framework Gorm
由于使用flash存放参数时,擦除掉了flash的代码区导致进入硬件错误中断
我们认为消费互联网发展到最后,依然会局限于互联网行业本身
Qt QTableView数据列宽度自适应
RPC Technology
【MATLAB】MATLAB 仿真模拟调制系统 — AM 已调信号的功率谱与相干解调
AcWing第 58 场周赛