Mémoire 2/4
Challenge
Solution
$ volatility3 -f memory.vmem windows.filescan.FileScan | grep -i ".doc"
0x9603532d0b90 \Users\Aramis\Documents 216
0x9603532d2c60 \Users\Aramis\Documents 216
0x960358086c10 \Users\Aramis\Documents\Portos.docm 216
0x9603580a4710 \Users\Aramis\Documents\Portos.docm 216
0x9603580a7460 \Users\Aramis\Documents\Portos.docm 216
0x960358343820 \Users\Aramis\Documents 216
0x960358346ed0 \Users\Aramis\Documents 216
0x960358359300 \Users\Aramis\Documents 216
0x960358363ee0 \Users\Public\Documents\desktop.ini 216
Mis à jour