Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CreateForensicsDirectory ¶
CreateForensicsDirectory input: Path to direcctory to save forensic data If directory exists it skips, else create it. CreateForensicsDirectory output: Return boolean reult and on failure return error
func MemoryDump ¶
func MemoryDump(foresincDataDirectory string, pid int, verification int, winAppDataDirPath string, dumpItExecutable *byteexec.Exec, procDumpExecutable *byteexec.Exec) (bool, string, error)
MemoryDump input: foresincDataDirectory, pid If PID is provided it will proceed with a memory dump of that process, else will default to a full memory dump MemoryDump output: Returns result, name of new dump (if sucessful), and status
Types ¶
This section is empty.
Click to show internal directories.
Click to hide internal directories.