Hackvent_2023/Day 6/extract.sh

4 lines
155 B
Bash

vol -f memory.raw windows.info
vol -f memory.raw windows.filescan | grep -i "png\|jpg\|jpeg"
vol -f memory.raw windows.dumpfiles --virtaddr 0x918b76c517f0