volatility
volatility copied to clipboard
Comparing Volatility Dumps
Is there a tool or option to compare two memory-dumps from the same machine? Let's say dump 1 is clean and dump 2 is infected with the malware - is there a way to execute a diff with the results?