Determine the footprint of .exe Start procmon Start your process Stop your process Stop the procmon capture Find first instance of your process as “Process Name” Double click Find size
Capturing Memory How Much Memory Corruption Lab 2
procmon
Filter for your process
Process Name
cmd.exe it is
After exe Image is Loaded
Check the Event Properties
Size Looks like 0x59000 = 364,54410 Not bad for a simple command prompt.
Lab 4/16/2014 Memory Acquisition 1. Capture memory using winpmem.exe 2. Determine the memory footprint of winpmem.exe