July 13, 2022, 1:46 a.m. | /u/KillithidMindslayer

Computer Forensics www.reddit.com

Hi all. I've been poking around trying to analyze a pagefile and hiberfil I recovered, but for the life of me, I can't get volatility to play nice with me.
So for starters, I've confirmed via the registry that the processor is AMD64 architecture and that it's Windows 10 19041.1.vb_release.191206-1406. I've tried using volatility to convert to a raw image (vol -f file.sys imagecopy -O target.raw) and no matter what profile I apply - which, ostensibly should be Win10x64_19041 - …

amp computerforensics volatility

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Junior Cybersecurity Triage Analyst

@ Peraton | Linthicum, MD, United States

Associate Director, Operations Compliance and Investigations Management

@ Legend Biotech | Raritan, New Jersey, United States

Analyst, Cyber Operations Engineer

@ BlackRock | SN6-Singapore - 20 Anson Road

Working Student/Intern/Thesis: Hardware based Cybersecurity Training (m/f/d)

@ AVL | Regensburg, DE