这题蛮鬼的,就,没有捷径,捷径导出文件一定是坏的
附件:mem.raw
[RoarCTF2019]forensic
1.volatility处理
λ volatility_2.6_win64_standalone.exe -f xxx7\Compressed\mem.raw imageinfo
Volatility Foundation Volatility Framework 2.6
INFO : volatility.debug : Determining profile based on KDBG search...
Suggested Profile(s) : Win7SP1x86_23418, Win7SP0x86, Win7SP1x86
AS Layer1 : IA32PagedMemoryPae (Kernel AS)
AS Layer2 : FileAddressSpace (\Compressed\mem.raw)
PAE type : PAE
DTB : 0x185000L
KDBG : 0x81729be8L
Number of Processors : 2
Image Type (Service