Using a pid in memory to identify the computername and username
I am new to digital forensics, and I’m practising cracking memory dumps. I have a pid with me which is 1764 and i need to extract the username and computer name of the dump file.
These are what i used so far and nothing worked.
C:\volatili… Continue reading Using a pid in memory to identify the computername and username