Malware Note
search
⌘Ctrlk
Malware Note
  • 恶意软件学习笔记
    • 服务
    • 启动项
    • 用户账户
    • DLL劫持
    • COM劫持
    • 映像劫持
    • 计划任务
    • WMI
    • Office
    • BITS Jobs
    • Rootkit
    • 未分类
    • LOLBin
    • Take a Test
    • createdump.exe
    • sihclient.exe
    • change.exe
    • ftp.exe
    • tpmtool.exe
    • tar.exe
    • curl.exe
    • IMEWDBLD.exe
    • Privileges
    • UAC Bypass
    • 漏洞
    • 错误配置
    • WMI
    • RPC
    • DCOM
    • HASH
    • Kerberos tickets
    • Office
    • LNK
    • PE
    • CHM
    • 注入
    • 反虚拟机/沙盒
    • SMB
    • 注入mstsc.exe
    • Mimikatz
    • NPLogonNotify
    • Tickets
    • 启动进程
    • 关闭WD
    • 绕过AMSI
    • MiniDumpWriteDump
    • Shellcode
    • SilentProcessExit
    • procdump
    • Task Manager/Process Explorer
    • Sqldumper
    • comsvcs.dll
    • WinPmem
    • ProcessDump.exe
    • Dumpert
    • BSOD
    • PPLdump
    • Hibernation
    • Stealer
    • Hidden Remote
    • Untitled
    • 鬼知道有什么用的小知识
gitbook由 GitBook 提供支持gitbook
  1. Dump内存

WinPmem

参考链接:

LogoGitHub - ReversecLabs/physmem2profit: Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotelyGitHubchevron-right

上一页comsvcs.dllchevron-left下一页ProcessDump.exechevron-right

最后更新于 4年前