3

Volatility suggests two profiles for XP memory dump. Which one should I use for further investigation? I am a beginner for the volatility.

Limit
  • 3,191
  • 1
  • 16
  • 35
PEO
  • 33
  • 3

1 Answers1

3

You should try both!

If memory addresses and PID's appear with question marks around them, you should probably switch to the other profile.

The problem is volatility can recognize that it's a certain Windows XP release, but the identifiable properties of these 2 XP Versions overlap, and make them harder to distinguish.

When executing plugins such as connscan or proclist, the results might be a bit obscure when using the wrong profile, because the actual locations in memory of these objects might differ between the XP Versions.

You'll notice pretty fast if you're using the wrong profile.

Nomad
  • 2,359
  • 2
  • 11
  • 23