Maxim Suhanov presented winmem_decompress – a program that tries to extract compressed memory pages from page-aligned data. Such compressed memory pages can be found in virtual memory of Windows 8.1 & 10 operating systems. Learn more about the tool here.
↧