Processes in Memory Lab - Dean-116/SYS-140-dean GitHub Wiki

This lab showed me how to find info inside an image including the password hashes. The first thing I did was find out the date and time the image was created by using vol.exe and typing in a command. Then I put in a command to show me to show me the location of Firefox and its plist info. Using this info I found out the hash of the password for the example user Sarah's Firefox. This shows the important of resetting your computer so it does not keep this data saved. I then took the first mentioned image outside of Firefox.