vol_cmdline
Pull process command lines from Windows memory images to identify executed commands and aid forensic investigations.
Instructions
Volatility3 windows.cmdline — process command lines from memory.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| source | Yes | ||
| image_path | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tool | Yes | ||
| source | Yes | ||
| preview | Yes | First rows only; query the rest via artifact_query | |
| row_count | Yes | ||
| artifact_id | Yes | Cite this id in findings (artifact_refs) | |
| payload_sha256 | Yes |