What command is used to determine the OS profile of a memory dump?, vol.py imageinfo -f <memory dump>, vol.py netscan -f <memory dump>, vol.py pslist -f <memory dump>, vol.py psscan -f <memory dump>, Which Volatility plugin lists all running processes in a memory dump?, pslist, netscan, malfind, dlllist, Which Volatility plugin is used to display the hierarchical structure of processes?, psscan, pstree, handles, hivelist, Which plugin is used to find hidden or unlinked processes?, dlllist, malfind, psscan, vadinfo, Which plugin is used to identify malicious code injections?, hivelist, malfind, pslist, dlllist, Which Volatility command is used to dump memory from a suspicious process?, vol.py dumpit -f tb.vmem, vol.py vaddump -f tb.vmem -p <PID> -D <directory>, vol.py handles -f tb.vmem, vol.py printkey -f tb.vmem, Which registry key is commonly checked for malware persistence?, Software\Microsoft\Windows\CurrentVersion\Run, System\CurrentControlSet\Services\TCP, Software\Microsoft\Windows\ShellNoChange, Software\Microsoft\Windows\NetworkAccess, Which process is most likely responsible for sending exfiltrated data via POST requests?, svchost.exe, explorer.exe, notepad.exe, winlogon.exe, Where can you submit file hashes to identify malware?, VirusTotal, Shodan, Google, Whois, Which command is used to search for specific keywords in dumped memory?, grep "<search term>" ~/Desktop/output/strings/*.txt, vol.py netscan -f tb.vmem, vol.py handles -f tb.vmem, vol.py dlllist -f tb.vmem

ลีดเดอร์บอร์ด

สไตล์ภาพ

ตัวเลือก

สลับแม่แบบ

คืนค่าการบันทึกอัตโนมัติ: ใช่ไหม