carnal0wnage.attackresearch.com
Finding malicious DLLs with Volatility
Colin and I were working on an memory image the other day and needed to find DLLs loaded by svchost.exe. We turned to everyone's default mem...