Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / MEMORY / DUMP / VOLATILITY / Processes

psxview

Usage

  • Cross-view detection
MethodSource
pslistActiveProcess linked list
psscanPool scan
thrdprocThread → EPROCESS back-reference
pspcidPspCidTable (PID table)
sessionSession process list
deskthrdDesktop thread list

If present in:

  • psscan
  • thrdproc
  • pspcid

But NOT in:

  • pslist → Likely DKOM hiding.

Commands

# Cross-check process visibility across structures (Vol2)  
vol.py -f <mem> --profile=<profile> psxview