Hackvent_2023/Day 06/extract.sh

4 lines
155 B
Bash
Raw Permalink Normal View History

2023-12-18 16:02:49 +01:00
vol -f memory.raw windows.info
vol -f memory.raw windows.filescan | grep -i "png\|jpg\|jpeg"
vol -f memory.raw windows.dumpfiles --virtaddr 0x918b76c517f0