TrueSecrets
Description
Source
➜ 7z l .\TrueSecrets.zip
Date Time Attr Size Compressed Name
------------------- ----- ------------ ------------ ------------------------
2022-12-14 19:34:32 ..... 209649664 78802404 TrueSecrets.raw
------------------- ----- ------------ ------------ ------------------------
2022-12-14 19:34:32 209649664 78802404 1 files
➜ 7z x .\TrueSecrets.zip -p'hackthebox'
└─$ file TrueSecrets.raw
TrueSecrets.raw: dataSolution
└─$ vol3 -f TrueSecrets.raw windows.info.Info | tee windows.info.log
Volatility 3 Framework 2.7.0
Progress: 100.00 PDB scanning finished
Variable Value
Kernel Base 0x82606000
DTB 0x185000
Symbols file:///home//.local/lib/python3.11/site-packages/volatility3/symbols/windows/ntkrpamp.pdb/92D32EE7188A4CB3AB23EDA0CB0F9D7B-2.json.xz
Is64Bit False
IsPAE True
layer_name 0 WindowsIntelPAE
memory_layer 1 FileLayer
KdDebuggerDataBlock 0x82732c78
NTBuildLab 7601.23915.x86fre.win7sp1_ldr.17
CSDVersion 1
KdVersionBlock 0x82732c50
Major/Minor 15.7601
MachineType 332
KeNumberProcessors 1
SystemTime 2022-12-14 21:33:30
NtSystemRoot C:\Windows
NtProductType NtProductWinNt
NtMajorVersion 6
NtMinorVersion 1
PE MajorOperatingSystemVersion 6
PE MinorOperatingSystemVersion 1
PE Machine 332
PE TimeDateStamp Wed Sep 13 14:47:57 2017
Last updated