QuestionQ243
Tools/Systems/ProgramsHenry, a forensic investigator, is analyzing a system suspected of compromise by a stealthy rootkit. The rootkit appears sophisticated and is concealing its files and processes to evade detection. Henry decides to perform memory and registry analysis to reveal the hidden rootkit. Which of the following tools is the best choice for Henry’s task?
- A RegRipper
- B Volatility
- C Dumplt
- D Autopsy
Community Discussion