Memory Forensics

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.

仅含说明Security
AI 生成的概览

指导内存取证:获取内存转储并用 Volatility 分析,用于事件响应与恶意软件分析。

功能
该技能提供内存取证的操作指引。内容涵盖 Windows、Linux 和 macOS 的实时内存获取、虚拟机内存捕获,以及使用 Volatility 3 命令进行分析的流程,包括进程列表、网络连接、注入检测、持久化与凭据提取。它还记录了 EPROCESS、PEB、VAD 等 Windows 内核结构、进程注入与 rootkit 的检测模式、用于内存扫描的 YARA 规则示例,以及使用 strings 和 FLOSS 的字符串分析。产出是操作说明与命令参考,而非生成的文件。
适用场景
适用于在事件响应或入侵调查中分析内存转储,从内存镜像中提取注入代码、网络连接等恶意软件痕迹,或在关机前从运行中的系统获取易失性内存。
运行要求
需要内存镜像以及 Volatility 3 等内存取证工具,并配合获取工具(WinPmem、DumpIt、LiME、osxpmem)和 strings、FLOSS、YARA 等实用程序来完成所述流程。该技能不附带脚本,仅为说明文档,另有一个补充参考文件。

Memory Forensics

Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.

When to Use This Skill

  • Performing memory analysis during incident response or breach investigation
  • Extracting malware artifacts (processes, injected code, network connections) from a RAM capture
  • Acquiring volatile memory from a live Windows/Linux/macOS system before shutdown
  • Using Volatility 3 / Rekall to triage memory dumps
  • Recovering credentials, browser sessions, or open files from process memory

Memory Acquisition

Live Acquisition Tools

Windows
powershell
# WinPmem (Recommended)winpmem_mini_x64.exe memory.raw
# DumpItDumpIt.exe
# Belkasoft RAM Capturer# GUI-based, outputs raw format
# Magnet RAM Capture# GUI-based, outputs raw format
Linux
bash
# LiME (Linux Memory Extractor)sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)sudo dd if=/dev/mem of=memory.raw bs=1M
# /proc/kcore (ELF format)sudo cp /proc/kcore memory.elf
macOS
bash
# osxpmemsudo ./osxpmem -o memory.raw
# MacQuisition (commercial)

Virtual Machine Memory

bash
# VMware: .vmem file is raw memorycp vm.vmem memory.raw
# VirtualBox: Use debug consolevboxmanage debugvm "VMName" dumpvmcore --filename memory.elf
# QEMUvirsh dump <domain> memory.raw --memory-only
# Hyper-V# Checkpoint contains memory state

Detailed section: Volatility 3 Framework

Originally a 2680-byte section in this SKILL.md. Moved to references/details.md to fit Codex's 8 KB skill body cap.

Analysis Workflows

Malware Analysis Workflow

bash
# 1. Initial process surveyvol -f memory.raw windows.pstree > processes.txtvol -f memory.raw windows.pslist > pslist.txt
# 2. Network connectionsvol -f memory.raw windows.netscan > network.txt
# 3. Detect injectionvol -f memory.raw windows.malfind > malfind.txt
# 4. Analyze suspicious processesvol -f memory.raw windows.dlllist --pid <PID>vol -f memory.raw windows.handles --pid <PID>
# 5. Dump suspicious executablesvol -f memory.raw windows.pslist --pid <PID> --dump
# 6. Extract strings from dumpsstrings -a pid.<PID>.exe > strings.txt
# 7. YARA scanningvol -f memory.raw windows.yarascan --yara-rules malware.yar

Incident Response Workflow

bash
# 1. Timeline of eventsvol -f memory.raw windows.timeliner > timeline.csv
# 2. User activityvol -f memory.raw windows.cmdlinevol -f memory.raw windows.consoles
# 3. Persistence mechanismsvol -f memory.raw windows.registry.printkey \    --key "Software\Microsoft\Windows\CurrentVersion\Run"
# 4. Servicesvol -f memory.raw windows.svcscan
# 5. Scheduled tasksvol -f memory.raw windows.scheduled_tasks
# 6. Recent filesvol -f memory.raw windows.filescan | grep -i "recent"

Data Structures

Windows Process Structures

c
// EPROCESS (Executive Process)typedef struct _EPROCESS {    KPROCESS Pcb;                    // Kernel process block    EX_PUSH_LOCK ProcessLock;    LARGE_INTEGER CreateTime;    LARGE_INTEGER ExitTime;    // ...    LIST_ENTRY ActiveProcessLinks;   // Doubly-linked list    ULONG_PTR UniqueProcessId;       // PID    // ...    PEB* Peb;                        // Process Environment Block    // ...} EPROCESS;
// PEB (Process Environment Block)typedef struct _PEB {    BOOLEAN InheritedAddressSpace;    BOOLEAN ReadImageFileExecOptions;    BOOLEAN BeingDebugged;           // Anti-debug check    // ...    PVOID ImageBaseAddress;          // Base address of executable    PPEB_LDR_DATA Ldr;              // Loader data (DLL list)    PRTL_USER_PROCESS_PARAMETERS ProcessParameters;    // ...} PEB;

VAD (Virtual Address Descriptor)

c
typedef struct _MMVAD {    MMVAD_SHORT Core;    union {        ULONG LongFlags;        MMVAD_FLAGS VadFlags;    } u;    // ...    PVOID FirstPrototypePte;    PVOID LastContiguousPte;    // ...    PFILE_OBJECT FileObject;} MMVAD;
// Memory protection flags#define PAGE_EXECUTE           0x10#define PAGE_EXECUTE_READ      0x20#define PAGE_EXECUTE_READWRITE 0x40#define PAGE_EXECUTE_WRITECOPY 0x80

Detection Patterns

Process Injection Indicators

python
# Malfind indicators# - PAGE_EXECUTE_READWRITE protection (suspicious)# - MZ header in non-image VAD region# - Shellcode patterns at allocation start
# Common injection techniques# 1. Classic DLL Injection#    - VirtualAllocEx + WriteProcessMemory + CreateRemoteThread
# 2. Process Hollowing#    - CreateProcess (SUSPENDED) + NtUnmapViewOfSection + WriteProcessMemory
# 3. APC Injection#    - QueueUserAPC targeting alertable threads
# 4. Thread Execution Hijacking#    - SuspendThread + SetThreadContext + ResumeThread

Rootkit Detection

bash
# Compare process listsvol -f memory.raw windows.pslist > pslist.txtvol -f memory.raw windows.psscan > psscan.txtdiff pslist.txt psscan.txt  # Hidden processes
# Check for DKOM (Direct Kernel Object Manipulation)vol -f memory.raw windows.callbacks
# Detect hooked functionsvol -f memory.raw windows.ssdt  # System Service Descriptor Table
# Driver analysisvol -f memory.raw windows.driverscanvol -f memory.raw windows.driverirp

Credential Extraction

bash
# Dump hashes (requires hivelist first)vol -f memory.raw windows.hashdump
# LSA secretsvol -f memory.raw windows.lsadump
# Cached domain credentialsvol -f memory.raw windows.cachedump
# Mimikatz-style extraction# Requires specific plugins/tools

YARA Integration

Writing Memory YARA Rules

yara
rule Suspicious_Injection{    meta:        description = "Detects common injection shellcode"
    strings:        // Common shellcode patterns        $mz = { 4D 5A }        $shellcode1 = { 55 8B EC 83 EC }  // Function prologue        $api_hash = { 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 }  // Push hash, call
    condition:        $mz at 0 or any of ($shellcode*)}
rule Cobalt_Strike_Beacon{    meta:        description = "Detects Cobalt Strike beacon in memory"
    strings:        $config = { 00 01 00 01 00 02 }        $sleep = "sleeptime"        $beacon = "%s (admin)" wide
    condition:        2 of them}

Scanning Memory

bash
# Scan all process memoryvol -f memory.raw windows.yarascan --yara-rules rules.yar
# Scan specific processvol -f memory.raw windows.yarascan --yara-rules rules.yar --pid 1234
# Scan kernel memoryvol -f memory.raw windows.yarascan --yara-rules rules.yar --kernel

String Analysis

Extracting Strings

bash
# Basic string extractionstrings -a memory.raw > all_strings.txt
# Unicode stringsstrings -el memory.raw >> all_strings.txt
# Targeted extraction from process dumpvol -f memory.raw windows.memmap --pid 1234 --dumpstrings -a pid.1234.dmp > process_strings.txt
# Pattern matchinggrep -E "(https?://|[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})" all_strings.txt

FLOSS for Obfuscated Strings

bash
# FLOSS extracts obfuscated stringsfloss malware.exe > floss_output.txt
# From memory dumpfloss pid.1234.dmp

Best Practices

Acquisition Best Practices

  1. Minimize footprint: Use lightweight acquisition tools
  2. Document everything: Record time, tool, and hash of capture
  3. Verify integrity: Hash memory dump immediately after capture
  4. Chain of custody: Maintain proper forensic handling

Analysis Best Practices

  1. Start broad: Get overview before deep diving
  2. Cross-reference: Use multiple plugins for same data
  3. Timeline correlation: Correlate memory findings with disk/network
  4. Document findings: Keep detailed notes and screenshots
  5. Validate results: Verify findings through multiple methods

Common Pitfalls

  • Stale data: Memory is volatile, analyze promptly
  • Incomplete dumps: Verify dump size matches expected RAM
  • Symbol issues: Ensure correct symbol files for OS version
  • Smear: Memory may change during acquisition
  • Encryption: Some data may be encrypted in memory

来源与署名

来源:wshobson/agents位于plugins/reverse-engineering/skills/memory-forensics提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架