python3 vol.py -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.info
sha256sum 20210430-Win10Home-20H2-64bit-memdump.mem
python3 vol.py -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.pstree
python3 vol.py -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.netscan | grep "ESTABLISHED"
python3 vol.py -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.netscan | grep "chrome"
python3 vol.py -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.pslist --pid 6988 --dump
md5sum pid.6988.0x1c0000.dmp
xxd --seek 0x45BE876 20210430-Win10Home-20H2-64bit-memdump.mem | less
python3 vol.py -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.cmdline | grep "notepad"
python3 vol.py -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.registry.userassist | grep "Brave"