This is a memory dump of compromised system, do some forensics kung-fu to explore the inside.
The Following Room is walkthrough of Forensics Machine of tryhackme
So First Start with checking the info
$ volatility -f victim.raw imageinfo
we will go with profile
Win7SP1x64
The OS is windows
Now
$volatility -f victim.raw --profile=Win7SP1x64 pslist
So we got the pid of searchindexer
To check for the last directory
$volatility -f victim.raw --profile=Win7SP1x64 shellbags
Scanning Networks
$volatility -f victim.raw --profile=Win7SP1x64 netscan
$volatility -f victim.raw --profile=Win7SP1x64 malfind -D .
The Process Ids are 1860;1820;2464
Lets find out URLs.
Now lets search for ips.
Its was really new for me to do forensics and this machine is good.
I highly recommend to to https://tryhackme.com/room/bpvolatility this room before doing forensics
Comments
Post a Comment