Downloading sample memory dump files
For this chapter, we’ll be using a memory dump called cridex.vmem
, which we will be analyzing using a variety of Volatility 3 plugins. The file can be downloaded from http://files.sempersecurus.org/dumps/cridex_memdump.zip.
There are many other images that are publicly available for analysis at https://github.com/volatilityfoundation/volatility/wiki/Memory-Samples. To practice working with the Volatility framework and further enhance your analytical skills, you may wish to download as many images as you like and use the various plugins available in Volatility.
Let’s first download and extract our sample memory dump, which we will later move to our Volatility installation folder for analysis. If you haven’t already downloaded the file, please do so now.
I’ve downloaded the cridex.vem
sample file to my Downloads
folder. To extract the file, right-click on the file and click on Extract Here as you have done with...