See also memory dump article.
Usual stuff:
- grep
- strings
- hex editor
- …
Specialized software:
Thinks to look out for:
- System process with invalid parent process id. For example:
- Process system with a parent id (normally, there is always only one instance with no parent process).
- Process scvhost or svch0st (there is only svchost.exe)
- … (see also Incident response training March 2025)
Leave a Reply
You must be logged in to post a comment.