THE DFIR BLOG
Menu

Memory Forensics

Question 2:Let's start easy - whats the PC's name and IP address?

3/31/2019

 
Picture

vol.py -f OtterCTF.vmem --profile=Win7SP1x64 netscan
192.168.202.131



Comments are closed.

    Archives

    August 2019
    July 2019
    April 2019
    March 2019

    Categories

    All
    Ctf
    Defcon
    DFIR
    Forensics
    Memory
    Memory Forensics

    RSS Feed

  • Infosec
  • Mac Forensics
  • Windows Forensics
  • Linux Forensics
  • Memory Forensics
  • Incident Response
  • Blog
  • About Me
  • Infosec
  • Mac Forensics
  • Windows Forensics
  • Linux Forensics
  • Memory Forensics
  • Incident Response
  • Blog
  • About Me