2025/07/27/BelkaCTF-7-Volatility3-vs-MemProcFS #8
Replies: 1 comment 1 reply
-
|
This is just a guess, but it's probably how each has different way of carving files. |
Beta Was this translation helpful? Give feedback.
-
|
This is just a guess, but it's probably how each has different way of carving files. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
2025/07/27/BelkaCTF-7-Volatility3-vs-MemProcFS
I encountered an interesting situation during BelkaCTF 7. This is not a writeup for one of the challenges but will give the solution as part of examining the oddity I experienced. I’m hoping that someone might be able to shed some light on the reason for the difference or if I did something incorrectly. One of the challenges required dumping a process from memory for further analysis. What is baffling is that I’m pretty sure that Belkasoft X uses Volatility 3 for processing memory images. But using Volatility 3 manually did not work for me. I ended up getting the right answer with MemProcFS.
https://ogmini.github.io/2025/07/27/BelkaCTF-7-Volatility3-vs-MemProcFS.html
Beta Was this translation helpful? Give feedback.
All reactions