Nov. 28, 2023, 2:52 a.m. | /u/Iceman1123Trooper

Computer Forensics www.reddit.com

While reading through Chapter 18 of The Art of Memory Forensics textbook, I noticed the authors modified the *gh0st\_decode.py* script from the *chopshop* suite of tools to allow the decoded streams to be outputted in **body** **format**. I looked through the source code of *gh0st\_decode.py* to see if I could figure out a way to implement that functionality, but I couldn't find anything in the book, and Google isn't much help in this case, either. Has anyone successfully modified *gh0st\_decode.py* …

art authors body book code computerforensics file forensics memory memory forensics script source code tools

XDR Detection Engineer

@ SentinelOne | Italy

Security Engineer L2

@ NTT DATA | A Coruña, Spain

Cyber Security Assurance Manager

@ Babcock | Portsmouth, GB, PO6 3EN

Senior Threat Intelligence Researcher

@ CloudSEK | Bengaluru, Karnataka, India

Cybersecurity Analyst 1

@ Spry Methods | Washington, DC (Hybrid)

Security Infrastructure DevOps Engineering Manager

@ Apple | Austin, Texas, United States