Volatility, my own cheatsheet (Part 2): Processes and DLLs
Once identified the correct profile, we can start to analyze the processes in the memory and, when the dump come from a windows system, the loaded DLLs. pslist To list the processes of a system, use t