Memory analysis, part 2
MF and process memory dumping on Windows, collecting those all-too familiar details, page 156:
- process name and pid
- time information
- memory use
- mapping the process to its binary
- mapping the process to a user
- child processes and threads
- command line parameters
- file handles