From 0844929610893ca5e239037c1b1f2031316acbb2 Mon Sep 17 00:00:00 2001 From: Tejas <47889755+tejas15802@users.noreply.github.com> Date: Tue, 5 Jul 2022 19:45:13 +0530 Subject: [PATCH] Use same voltility3 version in documentation volatility3 2.0.1 --- doc/source/Linux.rst | 8 ++++---- doc/source/Windows.rst | 4 ++-- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/doc/source/Linux.rst b/doc/source/Linux.rst index 773aa80e4..8132453ce 100644 --- a/doc/source/Linux.rst +++ b/doc/source/Linux.rst @@ -74,7 +74,7 @@ I'd like to say thanks to `stuxnet `_ for provid $ python3 vol.py -f memory.vmem banners - Volatility 3 Framework 2.0.3 + Volatility 3 Framework 2.0.1 Progress: 100.00 PDB scanning finished Offset Banner @@ -96,7 +96,7 @@ If you do not find the ISF file then, please follow the instructions on :ref:`Li $ python3 vol.py -f memory.vmem linux.pslist - Volatility 3 Framework 2.0.3 Stacking attempts finished + Volatility 3 Framework 2.0.1 Stacking attempts finished PID PPID COMM @@ -123,7 +123,7 @@ If you do not find the ISF file then, please follow the instructions on :ref:`Li .. code-block:: shell-session $ python3 vol.py -f memory.vmem linux.pstree - Volatility 3 Framework 2.0.3 + Volatility 3 Framework 2.0.1 Progress: 100.00 Stacking attempts finished PID PPID COMM @@ -167,7 +167,7 @@ Now to find the commands ran in bash shell. Lets use ``linux.bash``. $ python3 vol.py -f memory.vmem linux.bash - Volatility 3 Framework 2.0.3 + Volatility 3 Framework 2.0.1 Progress: 100.00 Stacking attempts finished PID Process CommandTime Command diff --git a/doc/source/Windows.rst b/doc/source/Windows.rst index 3e6844f22..e722be0a3 100644 --- a/doc/source/Windows.rst +++ b/doc/source/Windows.rst @@ -45,7 +45,7 @@ In windows memory forensics using volatility3, most of the times we do not requi $ python3 vol.py -f MemDump.DMP windows.pslist | head -n 10 - Volatility 3 Framework 2.0.2 PDB scanning finished + Volatility 3 Framework 2.0.1 PDB scanning finished PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime File output @@ -61,7 +61,7 @@ In windows memory forensics using volatility3, most of the times we do not requi .. code-block:: shell-session $ python3 vol.py -f MemDump.DMP windows.pstree | head -n 20 - Volatility 3 Framework 2.0.2 PDB scanning finished + Volatility 3 Framework 2.0.1 PDB scanning finished PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime