vol_psscan
Find hidden and terminated processes in Windows memory images using pool-scanning techniques. Analyze process objects directly from memory to uncover evidence invisible to standard enumeration.
Instructions
Volatility3 windows.psscan — pool-scanned processes (finds hidden/terminated).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| source | Yes | ||
| image_path | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tool | Yes | ||
| source | Yes | ||
| preview | Yes | First rows only; query the rest via artifact_query | |
| row_count | Yes | ||
| artifact_id | Yes | Cite this id in findings (artifact_refs) | |
| payload_sha256 | Yes |