forensenellanebbia.blogspot.it - Forense nella Nebbia

Example domain paragraphs

I needed to analyze a memory dump with Volatility 2/3. These are the steps I followed to build a Linux profile based on Red Hat Enterprise Linux (RHEL) 5.11 x64 (kernel version 2.6.18-398). At the time of writing, the Volatility repository doesn't have a profile for this OS (1) . 

I installed RHEL511x64 on VMware Workstation v14 using default settings during setup (always press Next ). No updates once installed the OS. 

Since the VM was already running the kernel version I needed, from the mounted ISO I installed these packages that would be needed later (2) :