VolUtility
VolUtility copied to clipboard
Multiple Issues
- psscan give 0 result
- pstree is missing from list
- malsysproc is missing
- processbl and servicebl needed in order to compare img against a baseline img
- additional filers needed, like under handles if need to filter just one pid and just a type (something like run vol.py .... handles -p 1234 -t Key)
- mimikatz is missing
- it seems that printkey plugin doesn't give the same result than launching from command line (search for a key value)
- in moddump is possible to see result but not able to download
- need support for load the hybernation files?