Professional Documents
Culture Documents
Analyzing data from the acquired image file using related tools
1. Finding a specific process in a memory dump file using tool "Volatility"
- What is the PID # of "notepad.exe" in test2.img?
1568