Month of @volatility plugins teaser: Recovering .bash_history from memory, even in the face of anti-forensics: pastebin.com/Pj39TMrU #dfir
3
13
7
@attrc Ah, I gotcha-- identifying the bash processes and sucking the history out?
2
@hal_pomeranz yep using the structures in mem so u get time run and command together
1

