I’ve always loved this method for quick triage of memory images
#DFIR tip: You can trivially automate detection of known malware through the use of three @volatility plugins + a simple bash script + clamscan&yara: volatility-labs.blogspot.com…

Nov 2, 2019 · 6:32 PM UTC

2
1