1.查看基本信息
volatility_2.6_win64_standalone.exe -f F:\virusmachines\win7x64_pos\Win7x64\Win7x64-Snapshot4.vmem imageinfo
2.查看进程信息
volatility_2.6_win64_standalone.exe -f F:\virusmachines\win7x64_pos\Win7x64\Win7x64-Snapshot4.vmem --profile=Win7SP1x64 pslist
3.转储内存文件
volatility_2.6_win64_standalone.exe -f F:\virusmachines\win7x64_pos\Win7x64\Win7x64-Snapshot13.vmem --profile=Win7SP1x64 dlldump --dump-dir F:\temp