Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / MEMORY / DUMP / VOLATILITY / Modules

modscan

Pool scan for kernel modules

Usage

  • Hidden drivers
  • Unlinked kernel modules

Commands

# Scan for hidden kernel modules (Vol2)  
vol.py -f <mem> --profile=<profile> modscan  
  
# Scan for hidden kernel modules (Vol3)  
python3 vol.py -f <mem> windows.modscan