Memory Forensics

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.

僅含說明Security
AI 產生的概覽

指導記憶體鑑識:取得記憶體傾印並以 Volatility 分析,用於事件應變與惡意程式分析。

功能
此技能提供記憶體鑑識的操作指引。內容涵蓋 Windows、Linux 與 macOS 的即時記憶體取得、虛擬機記憶體擷取,以及使用 Volatility 3 指令進行分析的流程,包括行程清單、網路連線、注入偵測、持續性機制與憑證擷取。它也記錄了 EPROCESS、PEB、VAD 等 Windows 核心結構、行程注入與 rootkit 的偵測模式、用於記憶體掃描的 YARA 規則範例,以及使用 strings 與 FLOSS 的字串分析。產出是操作說明與指令參考,而非產生的檔案。
適用情境
適用於在事件應變或入侵調查中分析記憶體傾印,從記憶體映像中擷取注入程式碼、網路連線等惡意程式痕跡,或在關機前從執行中的系統取得揮發性記憶體。
執行需求
需要記憶體映像以及 Volatility 3 等記憶體鑑識工具,並搭配取得工具(WinPmem、DumpIt、LiME、osxpmem)與 strings、FLOSS、YARA 等公用程式來完成所述流程。此技能不附指令碼,僅為說明文件,另有一份補充參考檔案。

Memory Forensics

Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.

When to Use This Skill

  • Performing memory analysis during incident response or breach investigation
  • Extracting malware artifacts (processes, injected code, network connections) from a RAM capture
  • Acquiring volatile memory from a live Windows/Linux/macOS system before shutdown
  • Using Volatility 3 / Rekall to triage memory dumps
  • Recovering credentials, browser sessions, or open files from process memory

Memory Acquisition

Live Acquisition Tools

Windows
powershell
# WinPmem (Recommended)winpmem_mini_x64.exe memory.raw
# DumpItDumpIt.exe
# Belkasoft RAM Capturer# GUI-based, outputs raw format
# Magnet RAM Capture# GUI-based, outputs raw format
Linux
bash
# LiME (Linux Memory Extractor)sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)sudo dd if=/dev/mem of=memory.raw bs=1M
# /proc/kcore (ELF format)sudo cp /proc/kcore memory.elf
macOS
bash
# osxpmemsudo ./osxpmem -o memory.raw
# MacQuisition (commercial)

Virtual Machine Memory

bash
# VMware: .vmem file is raw memorycp vm.vmem memory.raw
# VirtualBox: Use debug consolevboxmanage debugvm "VMName" dumpvmcore --filename memory.elf
# QEMUvirsh dump <domain> memory.raw --memory-only
# Hyper-V# Checkpoint contains memory state

Detailed section: Volatility 3 Framework

Originally a 2680-byte section in this SKILL.md. Moved to references/details.md to fit Codex's 8 KB skill body cap.

Analysis Workflows

Malware Analysis Workflow

bash
# 1. Initial process surveyvol -f memory.raw windows.pstree > processes.txtvol -f memory.raw windows.pslist > pslist.txt
# 2. Network connectionsvol -f memory.raw windows.netscan > network.txt
# 3. Detect injectionvol -f memory.raw windows.malfind > malfind.txt
# 4. Analyze suspicious processesvol -f memory.raw windows.dlllist --pid <PID>vol -f memory.raw windows.handles --pid <PID>
# 5. Dump suspicious executablesvol -f memory.raw windows.pslist --pid <PID> --dump
# 6. Extract strings from dumpsstrings -a pid.<PID>.exe > strings.txt
# 7. YARA scanningvol -f memory.raw windows.yarascan --yara-rules malware.yar

Incident Response Workflow

bash
# 1. Timeline of eventsvol -f memory.raw windows.timeliner > timeline.csv
# 2. User activityvol -f memory.raw windows.cmdlinevol -f memory.raw windows.consoles
# 3. Persistence mechanismsvol -f memory.raw windows.registry.printkey \    --key "Software\Microsoft\Windows\CurrentVersion\Run"
# 4. Servicesvol -f memory.raw windows.svcscan
# 5. Scheduled tasksvol -f memory.raw windows.scheduled_tasks
# 6. Recent filesvol -f memory.raw windows.filescan | grep -i "recent"

Data Structures

Windows Process Structures

c
// EPROCESS (Executive Process)typedef struct _EPROCESS {    KPROCESS Pcb;                    // Kernel process block    EX_PUSH_LOCK ProcessLock;    LARGE_INTEGER CreateTime;    LARGE_INTEGER ExitTime;    // ...    LIST_ENTRY ActiveProcessLinks;   // Doubly-linked list    ULONG_PTR UniqueProcessId;       // PID    // ...    PEB* Peb;                        // Process Environment Block    // ...} EPROCESS;
// PEB (Process Environment Block)typedef struct _PEB {    BOOLEAN InheritedAddressSpace;    BOOLEAN ReadImageFileExecOptions;    BOOLEAN BeingDebugged;           // Anti-debug check    // ...    PVOID ImageBaseAddress;          // Base address of executable    PPEB_LDR_DATA Ldr;              // Loader data (DLL list)    PRTL_USER_PROCESS_PARAMETERS ProcessParameters;    // ...} PEB;

VAD (Virtual Address Descriptor)

c
typedef struct _MMVAD {    MMVAD_SHORT Core;    union {        ULONG LongFlags;        MMVAD_FLAGS VadFlags;    } u;    // ...    PVOID FirstPrototypePte;    PVOID LastContiguousPte;    // ...    PFILE_OBJECT FileObject;} MMVAD;
// Memory protection flags#define PAGE_EXECUTE           0x10#define PAGE_EXECUTE_READ      0x20#define PAGE_EXECUTE_READWRITE 0x40#define PAGE_EXECUTE_WRITECOPY 0x80

Detection Patterns

Process Injection Indicators

python
# Malfind indicators# - PAGE_EXECUTE_READWRITE protection (suspicious)# - MZ header in non-image VAD region# - Shellcode patterns at allocation start
# Common injection techniques# 1. Classic DLL Injection#    - VirtualAllocEx + WriteProcessMemory + CreateRemoteThread
# 2. Process Hollowing#    - CreateProcess (SUSPENDED) + NtUnmapViewOfSection + WriteProcessMemory
# 3. APC Injection#    - QueueUserAPC targeting alertable threads
# 4. Thread Execution Hijacking#    - SuspendThread + SetThreadContext + ResumeThread

Rootkit Detection

bash
# Compare process listsvol -f memory.raw windows.pslist > pslist.txtvol -f memory.raw windows.psscan > psscan.txtdiff pslist.txt psscan.txt  # Hidden processes
# Check for DKOM (Direct Kernel Object Manipulation)vol -f memory.raw windows.callbacks
# Detect hooked functionsvol -f memory.raw windows.ssdt  # System Service Descriptor Table
# Driver analysisvol -f memory.raw windows.driverscanvol -f memory.raw windows.driverirp

Credential Extraction

bash
# Dump hashes (requires hivelist first)vol -f memory.raw windows.hashdump
# LSA secretsvol -f memory.raw windows.lsadump
# Cached domain credentialsvol -f memory.raw windows.cachedump
# Mimikatz-style extraction# Requires specific plugins/tools

YARA Integration

Writing Memory YARA Rules

yara
rule Suspicious_Injection{    meta:        description = "Detects common injection shellcode"
    strings:        // Common shellcode patterns        $mz = { 4D 5A }        $shellcode1 = { 55 8B EC 83 EC }  // Function prologue        $api_hash = { 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 }  // Push hash, call
    condition:        $mz at 0 or any of ($shellcode*)}
rule Cobalt_Strike_Beacon{    meta:        description = "Detects Cobalt Strike beacon in memory"
    strings:        $config = { 00 01 00 01 00 02 }        $sleep = "sleeptime"        $beacon = "%s (admin)" wide
    condition:        2 of them}

Scanning Memory

bash
# Scan all process memoryvol -f memory.raw windows.yarascan --yara-rules rules.yar
# Scan specific processvol -f memory.raw windows.yarascan --yara-rules rules.yar --pid 1234
# Scan kernel memoryvol -f memory.raw windows.yarascan --yara-rules rules.yar --kernel

String Analysis

Extracting Strings

bash
# Basic string extractionstrings -a memory.raw > all_strings.txt
# Unicode stringsstrings -el memory.raw >> all_strings.txt
# Targeted extraction from process dumpvol -f memory.raw windows.memmap --pid 1234 --dumpstrings -a pid.1234.dmp > process_strings.txt
# Pattern matchinggrep -E "(https?://|[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})" all_strings.txt

FLOSS for Obfuscated Strings

bash
# FLOSS extracts obfuscated stringsfloss malware.exe > floss_output.txt
# From memory dumpfloss pid.1234.dmp

Best Practices

Acquisition Best Practices

  1. Minimize footprint: Use lightweight acquisition tools
  2. Document everything: Record time, tool, and hash of capture
  3. Verify integrity: Hash memory dump immediately after capture
  4. Chain of custody: Maintain proper forensic handling

Analysis Best Practices

  1. Start broad: Get overview before deep diving
  2. Cross-reference: Use multiple plugins for same data
  3. Timeline correlation: Correlate memory findings with disk/network
  4. Document findings: Keep detailed notes and screenshots
  5. Validate results: Verify findings through multiple methods

Common Pitfalls

  • Stale data: Memory is volatile, analyze promptly
  • Incomplete dumps: Verify dump size matches expected RAM
  • Symbol issues: Ensure correct symbol files for OS version
  • Smear: Memory may change during acquisition
  • Encryption: Some data may be encrypted in memory

來源與署名

來源:wshobson/agents位於plugins/reverse-engineering/skills/memory-forensics提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架