Sept. 5, 2022, 9:56 p.m. | /u/13pcfx37

Computer Forensics www.reddit.com

I want to know, how does Volatility know from a memory dump to which process a physical frame belongs to? I think I'm familiar with how the OS translates a virtual address to a physical.

So a virtual address space is split into pages. Each virtual address is translates to a physical address via page tables. A physical address is a memory address within a physical frame inside my memory dump. How does Volatility determine to which process a physical …

back computerforensics physical process translate volatility

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Information Security Engineer, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

BaaN IV Techno-functional consultant-On-Balfour

@ Marlabs | Piscataway, US

Senior Security Analyst

@ BETSOL | Bengaluru, India

Security Operations Centre Operator

@ NEXTDC | West Footscray, Australia

Senior Network and Security Research Officer

@ University of Toronto | Toronto, ON, CA