January 2020
Intermediate to advanced
448 pages
11h 42m
English
As was shown in the Redline section, it is necessary for responders to see what parent processes child processes are executed under. One indicator of a system being compromised is the identification of a process executed outside the normal parent process. The pstree plugin provides examiners with a tree-like structure that identifies the parent process that is executing a potential suspect process. The Cridex image is run with this plugin, utilizing the following command:
dfir@Desktop-SFARF6G~$ volatility -f cridex_laptop.mem -profile=WinXPSP2x86 pstreee
The command produces the following output:

An analysis of the results from ...
Read now
Unlock full access