July 19, 2022, 12:12 p.m. | /u/shikata_ganai

Computer Forensics www.reddit.com

Hello all!

I’ve hit a wall with volatility and am looking for advice on what I should do next. So far I have used the unloadedmodules plugin in volatility and have noticed some unloaded .sys files I want to carve out and analyze further. The plug-in displays the start and end address of the file in memory, but how do I use this information in volatility to carve out that section in memory? Any help would be greatly appreciated and …

computerforensics data end memory start

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Level 1 SOC Analyst

@ Telefonica Tech | Dublin, Ireland

Specialist, Database Security

@ OP Financial Group | Helsinki, FI

Senior Manager, Cyber Offensive Security

@ Edwards Lifesciences | Poland-Remote

Information System Security Officer

@ Booz Allen Hamilton | USA, AL, Huntsville (4200 Rideout Rd SW)

Senior Security Analyst - Protective Security (Open to remote across ANZ)

@ Canva | Sydney, Australia