Please enable JavaScript.
Coggle requires JavaScript to display documents.
Windows processes (psscan (psscan We came to the conclusion that it was…
Windows processes
psscan
psscan We came to the conclusion that it was terminated based on running additional plugins to try to enumerate process objects like loaded
DLLs and handles, all of which returned no results
-
Many of the Volatility plugins will allow you to specify a process by PID ("-p") or by physical offset ("-o").
-o latter might work when the PID is unrecognized
-
-
pstree
Show verbose information, including image path and
command line used for each process (-v)