vol_pslist
Extract the active process list from a Windows memory image using Volatility3 to identify running processes in a forensic investigation.
Instructions
Volatility3 windows.pslist — processes from the active process list.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| source | Yes | ||
| image_path | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tool | Yes | ||
| source | Yes | ||
| preview | Yes | First rows only; query the rest via artifact_query | |
| row_count | Yes | ||
| artifact_id | Yes | Cite this id in findings (artifact_refs) | |
| payload_sha256 | Yes |