volatility -f [image] --profile=[profile] [plugin]volatility -f xxx.vmem imageinfovolatility -f 1.vmem --profile=Win7SP1x64 hashdumpvolatility -f 1.vmem --profile=Win7SP1x64 pslistvolatility -f 1.vmem --profile=Win7SP1x64 svcscanvolatility -f 1.vmem --profile=Win7SP1x64 iehistoryvolatility -f 1.vmem --profile=Win7SP1x64 netscanvolatility -f 1.vmem --profile=Win7SP1x64 cmdscanvolatility -f 1.vmem --profile=Win7SP1x64 filescanvolatility -f 1.vmem --profile=Win7SP1x64 dumpfiles -Q 0xxxxxxxx -D ./volatility -f 1.vmem --profile=Win7SP1x64 notepadvolatility -f 1.vmem --profile=Win7SP1x64 memdump -p xxx --dump-dir=./volatility -f 1.vmem --profile=Win7SP1x64 screenshot --dump-dir=./volatility -f 1.vmem --profile=Win7SP1x64 hivelistvolatility -f 1.vmem --profile=Win7SP1x64 hivedump -o 0xfffff8a001032410volatility -f 1.vmem --profile=Win7SP1x64 printkey -K "xxxxxxx"volatility -f 1.vmem --profile=Win7SP1x64 userassistvolatility -f 1.vmem --profile=Win7SP1x64 timelinervolatility -f easy_dump.img imageinfo











#脚本文件
import matplotlib.pyplot as plt
import numpy as np
x = []
y = []
with open('hint.txt','r') as f:
datas = f.readlines()
for data in datas:
arr = data.split(' ')
x.append(int(arr[0]))
y.append(int(arr[1]))
plt.plot(x,y,'ks',ms=1)
plt.show()








E
N
D
本文作者:TideSec
本文为安全脉搏专栏作者发布,转载请注明:https://www.secpulse.com/archives/197037.html
必填 您当前尚未登录。 登录? 注册
必填(保密)