Dear All,
I'm a beginner in Memory Forensics, I want to develop volatility plugin that searches a memory dumps to find records which inserted via C++ program. I'm created VType for the struct that used in the program but how to access the records in memory dump using volatility.
thanks
regards,
Ahmad