Reveal Lab
Endpoint Forensics Lab
Last updated
Endpoint Forensics Lab
Last updated
First Of All to Answer This Endpoint Forensics Machine We looking for The Ps-List to determine what happened here BTW so after installing Volatility 3 From this Repository I use "-f " Paremeter and after that i give it the location of the file and use "windows.pstree" to determine the Ps-list and export it and there is the full command
Thanks for reading (: