<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="fr">
	<id>https://futex.re/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Volatility</id>
	<title>Volatility - Historique des versions</title>
	<link rel="self" type="application/atom+xml" href="https://futex.re/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Volatility"/>
	<link rel="alternate" type="text/html" href="https://futex.re/mediawiki/index.php?title=Volatility&amp;action=history"/>
	<updated>2026-04-19T14:07:12Z</updated>
	<subtitle>Historique des versions pour cette page sur le wiki</subtitle>
	<generator>MediaWiki 1.39.17</generator>
	<entry>
		<id>https://futex.re/mediawiki/index.php?title=Volatility&amp;diff=2521&amp;oldid=prev</id>
		<title>Futex le 1 juin 2015 à 13:06</title>
		<link rel="alternate" type="text/html" href="https://futex.re/mediawiki/index.php?title=Volatility&amp;diff=2521&amp;oldid=prev"/>
		<updated>2015-06-01T13:06:49Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Nouvelle page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Info sur le dump ==&lt;br /&gt;
  # ./vol.py -f ch2.dmp imageinfo&lt;br /&gt;
  Volatile Systems Volatility Framework 2.0&lt;br /&gt;
          Suggested Profile(s) : Win7SP1x86, Win7SP0x86&lt;br /&gt;
                     AS Layer1 : JKIA32PagedMemoryPae (Kernel AS)&lt;br /&gt;
                     AS Layer2 : FileAddressSpace (./ch2.dmp)&lt;br /&gt;
                      PAE type : PAE&lt;br /&gt;
                           DTB : 0x185000&lt;br /&gt;
&lt;br /&gt;
==Trouver le hostname ==&lt;br /&gt;
&lt;br /&gt;
  # ./vol.py -f ch2.dmp --profile=Win7SP0x86 envars&lt;br /&gt;
ou&lt;br /&gt;
  # ./vol.py -f ch2.dmp --profile Win7SP1x86 printkey -K &amp;quot;ControlSet001\Control\ComputerName\ActiveComputerName&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Trouver les hashs ==&lt;br /&gt;
&lt;br /&gt;
Afficher les ruches:&lt;br /&gt;
&lt;br /&gt;
  ./vol.py -f /tmp/e3a902d4d44e0f7bd9cb29865e0a15de.dmp --profile Win7SP1x86 hivelist&lt;br /&gt;
  Volatile Systems Volatility Framework 2.1&lt;br /&gt;
  Virtual    Physical   Name&lt;br /&gt;
  ---------- ---------- ----&lt;br /&gt;
  0x8ee66740 0x141c0740 \SystemRoot\System32\Config\SOFTWARE&lt;br /&gt;
  0x90cab9d0 0x172ab9d0 \SystemRoot\System32\Config\DEFAULT&lt;br /&gt;
  0x9670e9d0 0x1ae709d0 \??\C:\Users\John Doe\ntuser.dat&lt;br /&gt;
  0x9670f9d0 0x04a719d0 \??\C:\Users\John Doe\AppData\Local\Microsoft\Windows\UsrClass.dat&lt;br /&gt;
  0x9aad6148 0x131af148 \SystemRoot\System32\Config\SAM&lt;br /&gt;
  0x9ab25008 0x14a61008 \SystemRoot\System32\Config\SECURITY&lt;br /&gt;
  0x9aba79d0 0x11a259d0 \??\C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT&lt;br /&gt;
  0x9abb1720 0x0a7d4720 \??\C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT&lt;br /&gt;
  0x82b6b140 0x02b6b140 [no name]&lt;br /&gt;
  0x8b20c008 0x039e1008 [no name]&lt;br /&gt;
  0x8b21c008 0x039ef008 \REGISTRY\MACHINE\SYSTEM&lt;br /&gt;
  0x8b23c008 0x02ccf008 \REGISTRY\MACHINE\HARDWARE&lt;br /&gt;
  0x8ee66008 0x141c0008 \Device\HarddiskVolume1\Boot\BCD&lt;br /&gt;
&lt;br /&gt;
Extraction des pass NTLM&lt;br /&gt;
  ./vol.py -f /tmp/e3a902d4d44e0f7bd9cb29865e0a15de.dmp --profile Win7SP1x86 hashdump -y 0x8b21c008 -s 0x9aad6148&lt;br /&gt;
  Volatile Systems Volatility Framework 2.1&lt;br /&gt;
  Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::&lt;br /&gt;
  Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::&lt;br /&gt;
  John Doe:1000:aad3b435b51404eeaad3b435b51404ee:b9f917853e3dbf6e6831ecce60725930:::&lt;br /&gt;
&lt;br /&gt;
== Variables d&amp;#039;environnement ==&lt;br /&gt;
Location du dump mémoire&lt;br /&gt;
  export VOLATILITY_LOCATION=file:///$(pwd)/dump/dump&lt;br /&gt;
&lt;br /&gt;
Profile du dump&lt;br /&gt;
  export VOLATILITY_PROFILE=Win7SP1x64&lt;/div&gt;</summary>
		<author><name>Futex</name></author>
	</entry>
</feed>