Let's perform the following steps:
- Volatility is already installed in Kali. Let's run the framework to see the details of the image we have. Run the following command:
volatility -f ch2.dmp imageinfo
Once we run the preceding command, we get the following output:
- The preceding screenshot shows us the information pertaining to the image, such as the Image Date and Number of Processors. It also suggests the profile to use for further analysis. Use Win7SP1x86 for now. Let's try to find the hostname of the system whose image we are analyzing. For this, look at the SYSTEM hive in the registry. This hive contains the hostname ...