Tags: keepass volatility 

Rating: 5.0

**tl;dr**

* File recovery from the memory dump
* Environment variables analysis.
* RAR and Zip password cracking.
* Cracking Windows user password hash.
* Extracting Keepass Master Password from keystrokes of logged data.

Original writeup (https://blog.bi0s.in/2021/03/22/Forensics/KarDi-Bee-X-Securinets-Quals-2021/).