Questions
As we conclude, here is a list of questions for you to test your knowledge regarding this chapter's material. You will find the answers in the Assessments section of the Appendix:
- Which is the master table name in
SQLite3
that stores all the table names? - What are the Volatility plugins we can use to list the running processes from the memory image?
- What is the name of the registry key we can use from the Windows registry to obtain information relating to the software installed?
- What is the name of the registry key we can use from the Windows registry to obtain information about services that are running in the operating system?
- What is the handler that has the capacity to write log messages to a standard file and provides automatic rotation in the log file?