Magnet Virtual Summit 2020 CTF — Memory

How’s Your Memory? -f memdump.mem imageinfo

Hash Slinging -f memdump.mem --profile=Win7SP1x64 hashdump

Cache Money -f memdump.mem --profile=Win7SP1x64 filescan > filescan.txtcat filescan.txt | grep Chrome | grep -f memdump.mem --profile=Win7SP1x64 dumpfiles -Q 0x000000013fdc56b0 -n -D .

Never Tell Me The Odds…

IgnitionCasino.exe | 3b7ca3bb8d4fb2b6c287d6a247efd7c457937a3e

Compilation Station




