Memory Forensics

by wshobson46891e7e60daNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.

Instructions onlySecurity
AI-generated overview

Guides memory forensics: acquiring RAM dumps and analyzing them with Volatility for incident response and malware analysis.

What it does
This skill provides procedural guidance for memory forensics work. It covers live memory acquisition on Windows, Linux and macOS, virtual machine memory capture, and analysis workflows using Volatility 3 commands for process listing, network connections, injection detection, persistence and credential extraction. It also documents Windows kernel structures such as EPROCESS, PEB and VAD, detection patterns for process injection and rootkits, YARA rule examples for memory scanning, and string analysis with strings and FLOSS. The deliverable is instructions and command references rather than generated files.
When to use it
Use it when analyzing a memory dump during incident response or breach investigation, when extracting malware artifacts such as injected code or network connections from a RAM capture, or when acquiring volatile memory from a live system before shutdown.
Requirements
Requires a memory image and memory forensics tooling such as Volatility 3, plus acquisition tools (WinPmem, DumpIt, LiME, osxpmem) and utilities like strings, FLOSS and YARA for the described workflows. It ships no scripts; it is instructions only, with a supplementary reference file.

Memory Forensics

Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.

When to Use This Skill

  • Performing memory analysis during incident response or breach investigation
  • Extracting malware artifacts (processes, injected code, network connections) from a RAM capture
  • Acquiring volatile memory from a live Windows/Linux/macOS system before shutdown
  • Using Volatility 3 / Rekall to triage memory dumps
  • Recovering credentials, browser sessions, or open files from process memory

Memory Acquisition

Live Acquisition Tools

Windows
powershell
# WinPmem (Recommended)winpmem_mini_x64.exe memory.raw
# DumpItDumpIt.exe
# Belkasoft RAM Capturer# GUI-based, outputs raw format
# Magnet RAM Capture# GUI-based, outputs raw format
Linux
bash
# LiME (Linux Memory Extractor)sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)sudo dd if=/dev/mem of=memory.raw bs=1M
# /proc/kcore (ELF format)sudo cp /proc/kcore memory.elf
macOS
bash
# osxpmemsudo ./osxpmem -o memory.raw
# MacQuisition (commercial)

Virtual Machine Memory

bash
# VMware: .vmem file is raw memorycp vm.vmem memory.raw
# VirtualBox: Use debug consolevboxmanage debugvm "VMName" dumpvmcore --filename memory.elf
# QEMUvirsh dump <domain> memory.raw --memory-only
# Hyper-V# Checkpoint contains memory state

Detailed section: Volatility 3 Framework

Originally a 2680-byte section in this SKILL.md. Moved to references/details.md to fit Codex's 8 KB skill body cap.

Analysis Workflows

Malware Analysis Workflow

bash
# 1. Initial process surveyvol -f memory.raw windows.pstree > processes.txtvol -f memory.raw windows.pslist > pslist.txt
# 2. Network connectionsvol -f memory.raw windows.netscan > network.txt
# 3. Detect injectionvol -f memory.raw windows.malfind > malfind.txt
# 4. Analyze suspicious processesvol -f memory.raw windows.dlllist --pid <PID>vol -f memory.raw windows.handles --pid <PID>
# 5. Dump suspicious executablesvol -f memory.raw windows.pslist --pid <PID> --dump
# 6. Extract strings from dumpsstrings -a pid.<PID>.exe > strings.txt
# 7. YARA scanningvol -f memory.raw windows.yarascan --yara-rules malware.yar

Incident Response Workflow

bash
# 1. Timeline of eventsvol -f memory.raw windows.timeliner > timeline.csv
# 2. User activityvol -f memory.raw windows.cmdlinevol -f memory.raw windows.consoles
# 3. Persistence mechanismsvol -f memory.raw windows.registry.printkey \    --key "Software\Microsoft\Windows\CurrentVersion\Run"
# 4. Servicesvol -f memory.raw windows.svcscan
# 5. Scheduled tasksvol -f memory.raw windows.scheduled_tasks
# 6. Recent filesvol -f memory.raw windows.filescan | grep -i "recent"

Data Structures

Windows Process Structures

c
// EPROCESS (Executive Process)typedef struct _EPROCESS {    KPROCESS Pcb;                    // Kernel process block    EX_PUSH_LOCK ProcessLock;    LARGE_INTEGER CreateTime;    LARGE_INTEGER ExitTime;    // ...    LIST_ENTRY ActiveProcessLinks;   // Doubly-linked list    ULONG_PTR UniqueProcessId;       // PID    // ...    PEB* Peb;                        // Process Environment Block    // ...} EPROCESS;
// PEB (Process Environment Block)typedef struct _PEB {    BOOLEAN InheritedAddressSpace;    BOOLEAN ReadImageFileExecOptions;    BOOLEAN BeingDebugged;           // Anti-debug check    // ...    PVOID ImageBaseAddress;          // Base address of executable    PPEB_LDR_DATA Ldr;              // Loader data (DLL list)    PRTL_USER_PROCESS_PARAMETERS ProcessParameters;    // ...} PEB;

VAD (Virtual Address Descriptor)

c
typedef struct _MMVAD {    MMVAD_SHORT Core;    union {        ULONG LongFlags;        MMVAD_FLAGS VadFlags;    } u;    // ...    PVOID FirstPrototypePte;    PVOID LastContiguousPte;    // ...    PFILE_OBJECT FileObject;} MMVAD;
// Memory protection flags#define PAGE_EXECUTE           0x10#define PAGE_EXECUTE_READ      0x20#define PAGE_EXECUTE_READWRITE 0x40#define PAGE_EXECUTE_WRITECOPY 0x80

Detection Patterns

Process Injection Indicators

python
# Malfind indicators# - PAGE_EXECUTE_READWRITE protection (suspicious)# - MZ header in non-image VAD region# - Shellcode patterns at allocation start
# Common injection techniques# 1. Classic DLL Injection#    - VirtualAllocEx + WriteProcessMemory + CreateRemoteThread
# 2. Process Hollowing#    - CreateProcess (SUSPENDED) + NtUnmapViewOfSection + WriteProcessMemory
# 3. APC Injection#    - QueueUserAPC targeting alertable threads
# 4. Thread Execution Hijacking#    - SuspendThread + SetThreadContext + ResumeThread

Rootkit Detection

bash
# Compare process listsvol -f memory.raw windows.pslist > pslist.txtvol -f memory.raw windows.psscan > psscan.txtdiff pslist.txt psscan.txt  # Hidden processes
# Check for DKOM (Direct Kernel Object Manipulation)vol -f memory.raw windows.callbacks
# Detect hooked functionsvol -f memory.raw windows.ssdt  # System Service Descriptor Table
# Driver analysisvol -f memory.raw windows.driverscanvol -f memory.raw windows.driverirp

Credential Extraction

bash
# Dump hashes (requires hivelist first)vol -f memory.raw windows.hashdump
# LSA secretsvol -f memory.raw windows.lsadump
# Cached domain credentialsvol -f memory.raw windows.cachedump
# Mimikatz-style extraction# Requires specific plugins/tools

YARA Integration

Writing Memory YARA Rules

yara
rule Suspicious_Injection{    meta:        description = "Detects common injection shellcode"
    strings:        // Common shellcode patterns        $mz = { 4D 5A }        $shellcode1 = { 55 8B EC 83 EC }  // Function prologue        $api_hash = { 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 }  // Push hash, call
    condition:        $mz at 0 or any of ($shellcode*)}
rule Cobalt_Strike_Beacon{    meta:        description = "Detects Cobalt Strike beacon in memory"
    strings:        $config = { 00 01 00 01 00 02 }        $sleep = "sleeptime"        $beacon = "%s (admin)" wide
    condition:        2 of them}

Scanning Memory

bash
# Scan all process memoryvol -f memory.raw windows.yarascan --yara-rules rules.yar
# Scan specific processvol -f memory.raw windows.yarascan --yara-rules rules.yar --pid 1234
# Scan kernel memoryvol -f memory.raw windows.yarascan --yara-rules rules.yar --kernel

String Analysis

Extracting Strings

bash
# Basic string extractionstrings -a memory.raw > all_strings.txt
# Unicode stringsstrings -el memory.raw >> all_strings.txt
# Targeted extraction from process dumpvol -f memory.raw windows.memmap --pid 1234 --dumpstrings -a pid.1234.dmp > process_strings.txt
# Pattern matchinggrep -E "(https?://|[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})" all_strings.txt

FLOSS for Obfuscated Strings

bash
# FLOSS extracts obfuscated stringsfloss malware.exe > floss_output.txt
# From memory dumpfloss pid.1234.dmp

Best Practices

Acquisition Best Practices

  1. Minimize footprint: Use lightweight acquisition tools
  2. Document everything: Record time, tool, and hash of capture
  3. Verify integrity: Hash memory dump immediately after capture
  4. Chain of custody: Maintain proper forensic handling

Analysis Best Practices

  1. Start broad: Get overview before deep diving
  2. Cross-reference: Use multiple plugins for same data
  3. Timeline correlation: Correlate memory findings with disk/network
  4. Document findings: Keep detailed notes and screenshots
  5. Validate results: Verify findings through multiple methods

Common Pitfalls

  • Stale data: Memory is volatile, analyze promptly
  • Incomplete dumps: Verify dump size matches expected RAM
  • Symbol issues: Ensure correct symbol files for OS version
  • Smear: Memory may change during acquisition
  • Encryption: Some data may be encrypted in memory

Source and attribution

Source:wshobson/agentsinplugins/reverse-engineering/skills/memory-forensicsat commit46891e7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal