Memory Dumps (Volatility)
Big dump of the RAM on a system. Use tools like volatility to analyze the dumps and get information about what happened
$ du -h file.dmp
1.0G file.dmp
$ file file.dmp
file.dmp: dataVolatility
Finding the Profile (2 only)
Extra Profiles
Modules
Processes
Dump process
Command-line
Environment variables
Network
Registry
Filesystem
Miscellaneous
Internet Explorer history
Clipboard
Notepad content
Screenshot
Bash history
Dump certificates / SSL keys
Hashes
Last updated


