memory profile | WinXPSP2x86 (woops vol3 doesn’t use these) |
nt hash | 31d6cfe0d16ae931b73c59d7e0c089c0 |
password | |
antivirus | no |
keylogger pid | 2360 (I showed this) |
keylogger installed? | can’t tell |
keylogger running? | no |
remote access? | 5800;5900 |
memory sample? | mdd_1.3.exe |
what’s the difference?
what are some pieces of information you can get from a phone, but not a harddrive?