home

drop memory dump strings or vad export csv · detect executable memory regions not backed by any file on disk · classic indicator of shellcode injection fileless malware and process hollowing · runs locally

drop malfind / vadinfo / vad csv
or click
drop volatility malfind · vadinfo · vad csv
ready