Sierra Leone - Simple Forensic (forens)

vol -f ./memdump.mem windows.pslist
PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime File output
4 0 System 0xbe077a092040 148 - N/A False 2025-09-10 06:56:09.000000 UTC N/A Disabled
108 4 Registry 0xbe077a099080 4 - N/A False 2025-09-10 06:56:04.000000 UTC N/A Disabled
388 4 smss.exe 0xbe077ae4d040 2 - N/A False 2025-09-10 06:56:09.000000 UTC N/A Disabled
504 480 csrss.exe 0xbe077b007080 12 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
580 480 wininit.exe 0xbe077bc6f080 1 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
588 572 csrss.exe 0xbe077bc74140 15 - 1 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
688 572 winlogon.exe 0xbe077bce4080 5 - 1 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
720 580 services.exe 0xbe077bd190c0 7 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
740 580 lsass.exe 0xbe077bd2c080 10 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
872 720 svchost.exe 0xbe077bd8d280 11 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
892 580 fontdrvhost.ex 0xbe077bddb180 5 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
900 688 fontdrvhost.ex 0xbe077bdd9180 5 - 1 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1004 720 svchost.exe 0xbe077ca11300 11 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
440 720 svchost.exe 0xbe077ca84280 5 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1036 720 svchost.exe 0xbe077cb0d340 7 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1084 720 svchost.exe 0xbe077cb0f2c0 1 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1092 720 svchost.exe 0xbe077cb63340 3 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1164 688 dwm.exe 0xbe077cb41080 14 - 1 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1180 688 LogonUI.exe 0xbe077cb430c0 0 - 1 False 2025-09-10 06:56:10.000000 UTC 2025-09-10 06:56:36.000000 UTC Disabled
1196 720 svchost.exe 0xbe077cb45300 4 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1256 720 svchost.exe 0xbe077cbae340 5 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1388 720 svchost.exe 0xbe077cc130c0 7 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1456 720 svchost.exe 0xbe077cc88300 6 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1476 720 svchost.exe 0xbe077ccab300 2 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1500 720 svchost.exe 0xbe077cc35080 4 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1552 720 svchost.exe 0xbe077ccea300 3 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1568 720 svchost.exe 0xbe077ccc92c0 3 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1576 720 svchost.exe 0xbe077ccca080 3 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1696 720 svchost.exe 0xbe077cd43280 7 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1716 4 MemCompression 0xbe077cd42040 22 - N/A False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1756 720 svchost.exe 0xbe077cd65300 6 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1768 720 svchost.exe 0xbe077cd85080 2 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1868 720 svchost.exe 0xbe077ce3b340 1 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1880 720 svchost.exe 0xbe077ce3c080 2 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1892 720 svchost.exe 0xbe077ce3d080 6 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
1468 720 svchost.exe 0xbe077cf26300 12 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2172 720 svchost.exe 0xbe077a08e300 7 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2180 720 svchost.exe 0xbe077cfc8300 9 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2188 720 svchost.exe 0xbe077a0a20c0 3 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2216 720 svchost.exe 0xbe077a12b080 4 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2288 720 svchost.exe 0xbe077a0e7080 2 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2412 720 spoolsv.exe 0xbe07800c80c0 7 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2424 720 svchost.exe 0xbe07800c1340 5 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2476 720 svchost.exe 0xbe077a17c080 12 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2512 720 svchost.exe 0xbe077a16f080 5 - 0 False 2025-09-10 06:56:10.000000 UTC N/A Disabled
2720 720 svchost.exe 0xbe077a164080 22 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2728 720 svchost.exe 0xbe077a162080 9 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2736 720 svchost.exe 0xbe077a084080 10 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2744 720 svchost.exe 0xbe077bcda300 1 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2760 720 MpDefenderCore 0xbe07801a9080 10 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2768 720 svchost.exe 0xbe07801a6300 16 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2780 720 VGAuthService. 0xbe07801a8340 2 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2788 720 svchost.exe 0xbe07801a7080 3 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2812 720 vmtoolsd.exe 0xbe07801ad2c0 11 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2820 720 vm3dservice.ex 0xbe07801ab280 2 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2860 720 MsMpEng.exe 0xbe0780194080 27 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2868 720 svchost.exe 0xbe0780193280 4 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
2904 720 svchost.exe 0xbe078022f280 6 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3040 2820 vm3dservice.ex 0xbe07802d4080 2 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3056 720 svchost.exe 0xbe07802d7300 5 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3236 720 svchost.exe 0xbe07803a1300 2 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3364 720 svchost.exe 0xbe07803d2080 11 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3384 1696 sihost.exe 0xbe078039f300 8 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3456 720 SearchIndexer. 0xbe07804b0280 16 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3544 720 svchost.exe 0xbe0780506080 10 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3788 720 svchost.exe 0xbe0780564300 4 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3828 720 dllhost.exe 0xbe078058c2c0 10 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3928 1388 taskhostw.exe 0xbe078062a080 9 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3944 1388 MicrosoftEdgeU 0xbe078061f080 4 - 0 True 2025-09-10 06:56:11.000000 UTC N/A Disabled
4028 720 svchost.exe 0xbe0780623300 2 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3808 872 WmiPrvSE.exe 0xbe07805e62c0 12 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3724 872 dllhost.exe 0xbe07805d62c0 5 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
3876 720 svchost.exe 0xbe078084b2c0 3 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
4244 3876 ctfmon.exe 0xbe078089d0c0 16 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
4324 720 svchost.exe 0xbe0780925300 8 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
4364 688 userinit.exe 0xbe078093c080 0 - 1 False 2025-09-10 06:56:11.000000 UTC 2025-09-10 06:56:32.000000 UTC Disabled
4428 4364 explorer.exe 0xbe078093a080 88 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
4592 720 svchost.exe 0xbe0780a3b300 5 - 0 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
4824 720 svchost.exe 0xbe07805df300 7 - 1 False 2025-09-10 06:56:11.000000 UTC N/A Disabled
4980 720 msdtc.exe 0xbe0780c082c0 9 - 0 False 2025-09-10 06:56:12.000000 UTC N/A Disabled
5208 2736 AggregatorHost 0xbe07803d0080 2 - 0 False 2025-09-10 06:56:12.000000 UTC N/A Disabled
5284 872 StartMenuExper 0xbe0780c7e080 8 - 1 False 2025-09-10 06:56:12.000000 UTC N/A Disabled
5352 872 RuntimeBroker. 0xbe0780d96340 1 - 1 False 2025-09-10 06:56:12.000000 UTC N/A Disabled
5480 872 SearchApp.exe 0xbe077a0eb080 71 - 1 False 2025-09-10 06:56:12.000000 UTC N/A Disabled
5676 872 RuntimeBroker. 0xbe0780fa8340 12 - 1 False 2025-09-10 06:56:12.000000 UTC N/A Disabled
6020 872 LockApp.exe 0xbe0781289080 11 - 1 False 2025-09-10 06:56:13.000000 UTC N/A Disabled
6100 872 RuntimeBroker. 0xbe07812de340 3 - 1 False 2025-09-10 06:56:13.000000 UTC N/A Disabled
5768 720 svchost.exe 0xbe078114e300 2 - 0 False 2025-09-10 06:56:13.000000 UTC N/A Disabled
6844 720 svchost.exe 0xbe078082a080 1 - 0 False 2025-09-10 06:56:14.000000 UTC N/A Disabled
6948 720 svchost.exe 0xbe0781457340 4 - 0 False 2025-09-10 06:56:14.000000 UTC N/A Disabled
6396 720 NisSrv.exe 0xbe0781463080 7 - 0 False 2025-09-10 06:56:16.000000 UTC N/A Disabled
6596 872 RuntimeBroker. 0xbe07816230c0 2 - 1 False 2025-09-10 06:56:22.000000 UTC N/A Disabled
6688 4428 SecurityHealth 0xbe0780d7d0c0 1 - 1 False 2025-09-10 06:56:23.000000 UTC N/A Disabled
6704 720 SecurityHealth 0xbe0780d8a2c0 6 - 0 False 2025-09-10 06:56:23.000000 UTC N/A Disabled
6828 4428 vmtoolsd.exe 0xbe0780fe8080 8 - 1 False 2025-09-10 06:56:23.000000 UTC N/A Disabled
2104 4428 msedge.exe 0xbe0781541300 0 - 1 False 2025-09-10 06:56:24.000000 UTC 2025-09-10 10:48:19.000000 UTC Disabled
7724 720 svchost.exe 0xbe078192e080 3 - 0 False 2025-09-10 06:56:25.000000 UTC N/A Disabled
7952 720 svchost.exe 0xbe0780a7e340 7 - 0 False 2025-09-10 06:56:31.000000 UTC N/A Disabled
8080 872 TextInputHost. 0xbe078181e080 17 - 1 False 2025-09-10 06:56:36.000000 UTC N/A Disabled
1296 872 ApplicationFra 0xbe0781909080 5 - 1 False 2025-09-10 06:57:01.000000 UTC N/A Disabled
5988 720 svchost.exe 0xbe077cac7340 9 - 0 False 2025-09-10 06:58:11.000000 UTC N/A Disabled
6592 720 svchost.exe 0xbe0781848080 2 - 1 False 2025-09-10 06:58:11.000000 UTC N/A Disabled
6668 720 svchost.exe 0xbe077cc15280 3 - 0 False 2025-09-10 06:58:11.000000 UTC N/A Disabled
772 720 SgrmBroker.exe 0xbe07817a7080 7 - 0 False 2025-09-10 06:58:11.000000 UTC N/A Disabled
700 720 svchost.exe 0xbe07815e2080 7 - 0 False 2025-09-10 06:58:12.000000 UTC N/A Disabled
1636 720 svchost.exe 0xbe078180d080 4 - 0 False 2025-09-10 06:58:12.000000 UTC N/A Disabled
3436 720 svchost.exe 0xbe0781829080 8 - 0 False 2025-09-10 06:58:12.000000 UTC N/A Disabled
8184 720 svchost.exe 0xbe0780f7e340 0 - 0 False 2025-09-10 07:03:10.000000 UTC 2025-09-10 07:03:16.000000 UTC Disabled
5136 720 svchost.exe 0xbe078183c080 9 - 0 False 2025-09-10 07:09:02.000000 UTC N/A Disabled
4536 872 dllhost.exe 0xbe07814ca080 5 - 1 False 2025-09-10 07:09:18.000000 UTC N/A Disabled
7876 720 svchost.exe 0xbe0780fb7080 3 - 0 False 2025-09-10 07:09:26.000000 UTC N/A Disabled
6956 872 ShellExperienc 0xbe078178b080 13 - 1 False 2025-09-10 07:09:32.000000 UTC N/A Disabled
3348 872 RuntimeBroker. 0xbe07818c4080 4 - 1 False 2025-09-10 07:09:32.000000 UTC N/A Disabled
5408 720 svchost.exe 0xbe078132b300 4 - 0 False 2025-09-10 07:09:42.000000 UTC N/A Disabled
604 720 svchost.exe 0xbe07815d7300 3 - 0 False 2025-09-10 07:09:42.000000 UTC N/A Disabled
3372 720 svchost.exe 0xbe07818e6080 2 - 0 False 2025-09-10 07:11:13.000000 UTC N/A Disabled
7608 720 svchost.exe 0xbe0780451300 2 - 0 False 2025-09-10 07:25:58.000000 UTC N/A Disabled
2384 688 LogonUI.exe 0xbe0781792080 0 - 1 False 2025-09-10 07:52:10.000000 UTC 2025-09-10 08:00:31.000000 UTC Disabled
2072 872 SystemSettings 0xbe077ceaf080 18 - 1 False 2025-09-10 08:35:35.000000 UTC N/A Disabled
4480 872 UserOOBEBroker 0xbe0780832080 1 - 1 False 2025-09-10 08:35:36.000000 UTC N/A Disabled
912 720 svchost.exe 0xbe077ce83080 1 - 0 False 2025-09-10 08:49:37.000000 UTC N/A Disabled
3968 688 LogonUI.exe 0xbe078119d080 0 - 1 False 2025-09-10 09:44:23.000000 UTC 2025-09-10 10:23:51.000000 UTC Disabled
9104 720 svchost.exe 0xbe07831b6340 3 - 0 False 2025-09-10 10:23:47.000000 UTC N/A Disabled
1656 720 svchost.exe 0xbe078182f300 4 - 0 False 2025-09-10 10:34:00.000000 UTC N/A Disabled
2120 720 svchost.exe 0xbe0781df5300 5 - 0 False 2025-09-10 10:34:00.000000 UTC N/A Disabled
4904 720 svchost.exe 0xbe0783365080 5 - 0 False 2025-09-10 10:34:01.000000 UTC N/A Disabled
6188 720 svchost.exe 0xbe07845e70c0 3 - 0 False 2025-09-10 10:38:44.000000 UTC N/A Disabled
3300 2104 msedge.exe 0xbe0783252080 48 - 1 False 2025-09-10 10:48:19.000000 UTC N/A Disabled
4420 3300 msedge.exe 0xbe078334f080 7 - 1 False 2025-09-10 10:48:19.000000 UTC N/A Disabled
4532 3300 msedge.exe 0xbe0783325080 17 - 1 False 2025-09-10 10:48:19.000000 UTC N/A Disabled
7968 3300 msedge.exe 0xbe0781911080 17 - 1 False 2025-09-10 10:48:19.000000 UTC N/A Disabled
2300 3300 msedge.exe 0xbe078334a080 9 - 1 False 2025-09-10 10:48:19.000000 UTC N/A Disabled
4836 4428 CSG2025_Forens 0xbe078190a080 4 - 1 False 2025-09-10 10:48:46.000000 UTC N/A Disabled
5968 4836 conhost.exe 0xbe07833b5340 3 - 1 False 2025-09-10 10:48:46.000000 UTC N/A Disabled
7384 4428 CSG2025_Forens 0xbe07846ef080 4 - 1 False 2025-09-10 10:48:54.000000 UTC N/A Disabled
7392 7384 conhost.exe 0xbe0781269300 3 - 1 False 2025-09-10 10:48:54.000000 UTC N/A Disabled
4528 4428 CSG2025_Forens 0xbe078298b340 4 - 1 False 2025-09-10 10:48:58.000000 UTC N/A Disabled
1980 4528 conhost.exe 0xbe0783fa4300 3 - 1 False 2025-09-10 10:48:58.000000 UTC N/A Disabled
5424 4428 CSG2025_Forens 0xbe077cc87080 4 - 1 False 2025-09-10 10:49:03.000000 UTC N/A Disabled
4156 5424 conhost.exe 0xbe0781874300 3 - 1 False 2025-09-10 10:49:03.000000 UTC N/A Disabled
3004 4428 CSG2025_Forens 0xbe0783fb4300 4 - 1 False 2025-09-10 10:49:07.000000 UTC N/A Disabled
8140 3004 conhost.exe 0xbe0783393300 3 - 1 False 2025-09-10 10:49:07.000000 UTC N/A Disabled
3872 4428 CSG2025_Forens 0xbe07817e40c0 4 - 1 False 2025-09-10 10:49:10.000000 UTC N/A Disabled
3288 3872 conhost.exe 0xbe0782eed080 3 - 1 False 2025-09-10 10:49:10.000000 UTC N/A Disabled
7596 4428 CSG2025_Forens 0xbe0782fe1080 4 - 1 False 2025-09-10 10:49:15.000000 UTC N/A Disabled
3940 7596 conhost.exe 0xbe0782fcc080 3 - 1 False 2025-09-10 10:49:15.000000 UTC N/A Disabled
3212 4428 CSG2025_Forens 0xbe07831cb080 4 - 1 False 2025-09-10 10:49:19.000000 UTC N/A Disabled
6112 3212 conhost.exe 0xbe0780c80080 3 - 1 False 2025-09-10 10:49:19.000000 UTC N/A Disabled
6276 720 svchost.exe 0xbe078185c080 14 - 0 False 2025-09-10 10:49:19.000000 UTC N/A Disabled
472 4428 CSG2025_Forens 0xbe07831dc080 4 - 1 False 2025-09-10 10:49:27.000000 UTC N/A Disabled
7960 472 conhost.exe 0xbe0782a1c080 3 - 1 False 2025-09-10 10:49:27.000000 UTC N/A Disabled
128 4428 CSG2025_Forens 0xbe0782ee7080 4 - 1 False 2025-09-10 10:49:31.000000 UTC N/A Disabled
5880 128 conhost.exe 0xbe0782e96080 10 - 1 False 2025-09-10 10:49:31.000000 UTC N/A Disabled
7460 4428 notepad.exe 0xbe07814dc080 2 - 1 False 2025-09-10 10:49:57.000000 UTC N/A Disabled
8796 3456 SearchFilterHo 0xbe0780336080 4 - 0 False 2025-09-10 10:53:48.000000 UTC N/A Disabled
3804 3456 SearchProtocol 0xbe078130e080 6 - 1 False 2025-09-10 10:55:40.000000 UTC N/A Disabled
7272 872 smartscreen.ex 0xbe07811a2080 14 - 1 False 2025-09-10 10:55:54.000000 UTC N/A Disabled
8328 1468 audiodg.exe 0xbe077cdad080 5 - 0 False 2025-09-10 10:55:54.000000 UTC N/A Disabled
1224 4428 FTK Imager.exe 0xbe0782ee8080 23 - 1 False 2025-09-10 10:55:56.000000 UTC N/A Disabled

Last updated