exp0se / volatility-plugins

My Volatility plugins

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

vmtools plugin

This plugin will extract recently executed commands on a VMs via Vmware Tools. For example, via tools like PowerCLI, Ansible or custom tools, that leverage VMware API. Commands supported are:

  • Executed proccesses
  • File operations like copy and deletion

It also will extract credentials, that were used to run this command.

About

My Volatility plugins


Languages

Language:Python 100.0%