VolApihooks

Volatility script for command apihooks

javascript · Volatility (Deprecated)

Details

IDVolApihooks
Languagejavascript
From Version5.0.0
Tagsmemory forensics volatility server

README

Is a volatility script for command apihooks.

Script Data


Name Description
Script Type javascript
Tags memory, forensics, volatility, server

Inputs


Argument Name Description
memdump The path to memory dump file on the system being used.
system The system with Volatility installed to be used for the analysis.
pid The process ID to pass to Volatility as a parameter of the apihooks command.
profile The Volatility profile to use.

Outputs


There are no outputs for this script.

commonfields:
  id: VolApihooks
  version: -1
name: VolApihooks
script: ''
type: javascript
tags:
- memory
- forensics
- volatility
- server
comment: Volatility script for command apihooks
system: true
args:
- name: memdump
  required: true
  description: Path to memory dump file on the system being used
- name: system
  required: true
  description: System with Volatility installed to be used for the analysis
- name: pid
  description: Process ID to pass to volatility as a parameter of the apihooks command
- name: profile
  description: Volatility profile to use
scripttarget: 0
dependson: {}
timeout: 0s
fromversion: 5.0.0