Digital forensics chronicles: image identification issues on large memory dump with Volatility

Spoiler: shame on DumpIT! Some days ago, I was busy with a forensic analysis on a Windows server. The machine was a Windows Server 2008 R2, used as webserver, with 24 GB of RAM. But during memory analysis with Volatility, I hit a problem. The image identification process takes to long, and the found profile…

Article Link: https://www.andreafortuna.org/dfir/digital-forensics-chronicles-image-identification-issues-on-large-memory-dump-with-volatility/