Dec. 18, 2023, 12:37 p.m. | /u/13Cubed

Computer Forensics www.reddit.com

A new 13Cubed episode is up!

Learn how to properly acquire memory from Microsoft Hyper-V guest virtual machines.

After I recorded this episode, Ulf Frisk, the author of MemProcFS, let me know that he has made some updates that no longer require you to copy the vmsavedstatedumpprovider.dll file to the MemProcFS directory if the SDK is installed in the \*\*\*default\*\*\* location. If installed to a different location, the file must still be copied. Additionally, the requirement to prepend the Hyper-V …

author computerforensics copy directory dll dll file file forensics hyper-v learn machines memory memory forensics microsoft rescue updates virtual virtual machines

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC