volatility icon indicating copy to clipboard operation
volatility copied to clipboard

Memory Dump processing

Open W1z4rd-0n3 opened this issue 2 years ago • 0 comments

I am performing malware analysis using volatility 2.6. I collected the memory dump of a virtual box vm using vboxmanage dumpcore, and got a 4-5 GB memory dump. Volatility is taking too long to process this memory dump. Is there any way to collect the complete memory dump of windows 7 or 10 and reduce its size for volatility to digest it ?

W1z4rd-0n3 avatar Aug 01 '23 16:08 W1z4rd-0n3