The hivelist plugin

For more detailed (and helpful) information on registry hives and locations within RAM, the hivelist plugin can be used. The hivelist command shows the details of Virtual and Physical addresses along with the easier readable plaintext names and locations.

The command used to run hivelist is as follows:

volatility --profile=WinXPSP3x86 -f cridex.vmem hivelist
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset