volatility icon indicating copy to clipboard operation
volatility copied to clipboard

How to obtain own dump

Open vespertillo opened this issue 4 years ago • 1 comments

What is command for obtain dump of ram or entire OS(.iso,.dd,.img)? i try nofault app that generate system crash but after bsod and collect data dump no file on system memory.dmp any help? i use volatility 2.6 win64

vespertillo avatar May 13 '20 20:05 vespertillo

With the exception of old systems with FireWire and no DMA protection, Volatility is a tool for analysis only.

Can you please list the following:

  1. The OS version of the machine you generated the crash dump on

  2. The full input/output of Volatiltiy's pslist against the sample

Also, can you verify that you are using the latest code from Github?

atcuno avatar May 13 '20 21:05 atcuno