volatility 3

기본 포맷

python3 /home/kali/tools/volatility3/vol.py --write-config -f 'Windows 10 x64-b06241b1.vmem' windows.netscan |g

windows.info

windows.pslist 프로세스 리스트

windows.pstree

windows.cmdline

Windows.netscan