Volatility2 core commands
$ python vol.py -f $mem --profile=Win7SP1x64_23418 -h$ python vol.py -f $mem --profile=Win7SP1x64_23418 netscan
0x13d73d730 TCPv4 0.0.0.0:3389 0.0.0.0:0 LISTENING 1160 svchost.exe
0x13d73d730 TCPv6 :::3389 :::0 LISTENING 1160 svchost.exe
0x13f2e5010 TCPv4 192.168.10.146:54284 13.107.21.200:443 CLOSED -1
0x13f304280 TCPv4 192.168.10.146:54283 13.107.21.200:443 CLOSED -1$ python vol.py -f $mem --profile=Win7SP1x64_23418 pslist
Volatility Foundation Volatility Framework 2.6.1
Offset(V) Name PID PPID Thds Hnds Sess Wow64 Start Exit
------------------ -------------------- ------ ------ ------ -------- ------ ------ ------------------------------ ------------------------------
0xfffffa8030e57b00 System 4 0 108 572 ------ 0 2020-04-20 22:44:37 UTC+0000
0xfffffa8032005aa0 smss.exe 280 4 2 30 ------ 0 2020-04-20 22:44:37 UTC+0000
0xfffffa8032f05b00 csrss.exe 364 352 9 532 0 0 2020-04-20 22:44:38 UTC+0000
0xfffffa803254d580 wininit.exe 408 352 3 76 0 0 2020-04-20 22:44:38 UTC+0000
0xfffffa8032a29350 csrss.exe 440 416 11 534 1 0 2020-04-20 22:44:38 UTC+0000
0xfffffa803317e8e0 services.exe 472 408 7 241 0 0 2020-04-20 22:44:38 UTC+0000
0xfffffa8033197060 winlogon.exe 508 416 5 117 1 0 2020-04-20 22:44:38 UTC+0000
0xfffffa80331a7b00 lsass.exe 536 408 7 648 0 0 2020-04-20 22:44:38 UTC+0000
0xfffffa80331adb00 lsm.exe 544 408 10 211 0 0 2020-04-20 22:44:38 UTC+0000
0xfffffa8033227b00 svchost.exe 660 472 11 378 0 0 2020-04-20 22:44:38 UTC+0000
0xfffffa803325c060 vmacthlp.exe 728 472 3 66 0 0 2020-04-20 22:44:38 UTC+0000
0xfffffa8033266060 svchost.exe 772 472 10 336 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa80332b0b00 svchost.exe 860 472 21 514 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa80332fa5f0 svchost.exe 936 472 20 460 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa80333379b0 svchost.exe 980 472 15 655 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa803333db00 svchost.exe 112 472 44 1260 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa8033424860 svchost.exe 1160 472 21 668 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa803343eb00 spoolsv.exe 1304 472 13 287 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa80334d8b00 svchost.exe 1332 472 19 346 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa803357c5f0 svchost.exe 1444 472 10 146 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa80335e7720 VGAuthService. 1520 472 3 86 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa803364a060 vmtoolsd.exe 1576 472 10 289 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa80335edb00 wlms.exe 1636 472 4 46 0 0 2020-04-20 22:44:39 UTC+0000
0xfffffa8033735060 sppsvc.exe 1952 472 4 170 0 0 2020-04-20 22:44:40 UTC+0000
0xfffffa803362c060 svchost.exe 2032 472 6 105 0 0 2020-04-20 22:44:40 UTC+0000
0xfffffa803376e060 svchost.exe 1080 472 7 101 0 0 2020-04-20 22:44:40 UTC+0000
0xfffffa803379eb00 WmiPrvSE.exe 2108 660 12 221 0 0 2020-04-20 22:44:40 UTC+0000
0xfffffa80338145f0 dllhost.exe 2216 472 13 195 0 0 2020-04-20 22:44:40 UTC+0000
0xfffffa803386db00 msdtc.exe 2324 472 12 148 0 0 2020-04-20 22:44:40 UTC+0000
0xfffffa803365b060 svchost.exe 2944 472 9 136 0 0 2020-04-20 22:46:40 UTC+0000
0xfffffa80310b3b00 svchost.exe 360 472 13 361 0 0 2020-04-20 22:46:40 UTC+0000
0xfffffa8031090060 SearchIndexer. 2580 472 13 694 0 0 2020-04-20 22:46:41 UTC+0000
0xfffffa80316f9060 taskhost.exe 1396 472 10 223 1 0 2020-04-20 23:16:53 UTC+0000
0xfffffa8031ea9940 dwm.exe 2852 936 3 82 1 0 2020-04-20 23:16:53 UTC+0000
0xfffffa80317ff060 explorer.exe 2672 2148 31 1018 1 0 2020-04-20 23:16:53 UTC+0000
0xfffffa803140c5f0 WerFault.exe 2164 2508 5 133 1 0 2020-04-20 23:16:54 UTC+0000
0xfffffa8031e80b00 vmtoolsd.exe 2928 2672 9 178 1 0 2020-04-20 23:16:54 UTC+0000
0xfffffa80324e1940 audiodg.exe 1728 860 5 136 0 0 2020-04-20 23:16:54 UTC+0000
0xfffffa803165eb00 slack.exe 2208 2412 28 553 1 0 2020-04-20 23:16:54 UTC+0000
0xfffffa8031ed3710 slack.exe 2728 2208 9 213 1 0 2020-04-20 23:16:59 UTC+0000
0xfffffa8031471b00 slack.exe 1172 2208 7 135 1 0 2020-04-20 23:17:00 UTC+0000
0xfffffa8031688b00 slack.exe 2812 2208 15 325 1 0 2020-04-20 23:17:00 UTC+0000
0xfffffa80338cdb00 slack.exe 2848 2208 14 276 1 0 2020-04-20 23:17:00 UTC+0000
0xfffffa803177bb00 WINWORD.EXE 3180 2672 15 698 1 0 2020-04-20 23:17:06 UTC+0000
0xfffffa8031e2c2c0 chrome.exe 3384 2672 30 1039 1 0 2020-04-20 23:17:07 UTC+0000
0xfffffa8032429060 chrome.exe 3392 3384 7 95 1 0 2020-04-20 23:17:07 UTC+0000
0xfffffa803258cb00 wuauclt.exe 3464 112 3 94 1 0 2020-04-20 23:17:08 UTC+0000
0xfffffa80324ca5c0 chrome.exe 3492 3384 2 56 1 0 2020-04-20 23:17:09 UTC+0000Last updated