MEMORY FORENSICS WITH VOLATILITY 3
Complete guide to memory acquisition, analysis, and forensic investigation using Volatility 3 and supporting tools.
MEMORY ACQUISITION TOOLS#
Windows:
WinPmem:
winpmem_mini_x64.exe output.raw
winpmem_mini_x64.exe output.aff4 # AFF4 format
DumpIt (Comae):
DumpIt.exe # interactive, creates .dmp
DumpIt.exe /OUTPUT dump.raw /QUIET # non-interactive
FTK Imager:
File > Capture Memory > select output path
Belkasoft RAM Capturer:
GUI-based, minimal footprint
Magnet RAM Capture:
Free tool, simple GUI
Linux:
LiME (Linux Memory Extractor):
insmod lime.ko "path=/evidence/mem.lime format=lime"
insmod lime.ko "path=/evidence/mem.raw format=raw"
insmod lime.ko "path=tcp:4444 format=lime" # remote acquisition
AVML (Microsoft):
./avml /evidence/memory.lime
./avml --compress /evidence/memory.lime.compressed
/proc/kcore:
dd if=/proc/kcore of=/evidence/kcore bs=1M # not always reliable
fmem:
dd if=/dev/fmem of=/evidence/mem.raw bs=1M
macOS:
osxpmem:
sudo osxpmem -o /evidence/mem.aff4
sudo osxpmem --format raw -o /evidence/mem.raw
Virtual Machines:
VMware: .vmem file in VM directory (suspend VM first)
VirtualBox: vboxmanage debugvm <vm> dumpvmcore --filename mem.elf
Hyper-V: Checkpoint creates .bin memory files
QEMU/KVM: virsh dump <domain> mem.raw --memory-only
VOLATILITY 3 INSTALLATION#
# Install from pip pip3 install volatility3 # Install from source git clone https://github.com/volatilityfoundation/volatility3.git cd volatility3 pip3 install -r requirements.txt python3 vol.py -h # Install symbol tables (ISF) # Windows symbols download automatically # Linux: need to generate from kernel debug symbols # Place in volatility3/symbols/ directory # Basic syntax vol -f <memory_image> <plugin> python3 vol.py -f <memory_image> <plugin> # List available plugins vol -f image.raw --help
PROFILE DETECTION AND IMAGE INFO#
# Volatility 3 auto-detects OS (no manual profile needed) # To see image info: vol -f image.raw banners.Banners vol -f image.raw windows.info.Info vol -f image.raw linux.bash.Bash # If auto-detection fails, specify the OS: vol -f image.raw -o "output/" windows.pslist.PsList
WINDOWS PLUGINS - PROCESS ANALYSIS#
# List running processes vol -f image.raw windows.pslist.PsList vol -f image.raw windows.pslist.PsList --pid 1234 # Process tree (parent-child relationships) vol -f image.raw windows.pstree.PsTree # Scan for hidden/terminated processes (pool scanner) vol -f image.raw windows.psscan.PsScan # Compare pslist vs psscan to find hidden processes # Processes in psscan but not pslist may be hidden by rootkit # Process command line arguments vol -f image.raw windows.cmdline.CmdLine vol -f image.raw windows.cmdline.CmdLine --pid 1234 # Process environment variables vol -f image.raw windows.envars.Envars vol -f image.raw windows.envars.Envars --pid 1234 # Dump process executable vol -f image.raw windows.pslist.PsList --pid 1234 --dump
WINDOWS PLUGINS - DLL AND HANDLE ANALYSIS#
# List loaded DLLs per process vol -f image.raw windows.dlllist.DllList vol -f image.raw windows.dlllist.DllList --pid 1234 # List process handles (files, registry, mutexes) vol -f image.raw windows.handles.Handles vol -f image.raw windows.handles.Handles --pid 1234 # Filter handles by type vol -f image.raw windows.handles.Handles --pid 1234 --type File vol -f image.raw windows.handles.Handles --pid 1234 --type Key vol -f image.raw windows.handles.Handles --pid 1234 --type Mutant # SIDs associated with processes vol -f image.raw windows.getsids.GetSIDs # Privileges for processes vol -f image.raw windows.privileges.Privs vol -f image.raw windows.privileges.Privs --pid 1234
WINDOWS PLUGINS - NETWORK ANALYSIS#
# Network connections and listening sockets vol -f image.raw windows.netscan.NetScan vol -f image.raw windows.netstat.NetStat # Key fields: Owner (process), LocalAddr, ForeignAddr, State, Proto # Look for: # - Connections to known bad IPs # - Unusual ports (4444, 5555, 8080 from non-web processes) # - Processes that shouldn't have network connections # - Connections in ESTABLISHED state to external IPs
WINDOWS PLUGINS - MALWARE DETECTION#
# Detect injected code / hollowed processes vol -f image.raw windows.malfind.Malfind vol -f image.raw windows.malfind.Malfind --pid 1234 # Looks for: PAGE_EXECUTE_READWRITE memory regions with MZ headers # Dumps suspicious memory sections automatically # Detect API hooks (IAT/EAT/Inline) vol -f image.raw windows.ssdt.SSDT # Checks System Service Descriptor Table for hooks # Loaded kernel modules vol -f image.raw windows.modules.Modules vol -f image.raw windows.modscan.ModScan # Driver analysis vol -f image.raw windows.driverscan.DriverScan vol -f image.raw windows.driverirp.DriverIrp # Detect code injection via VAD (Virtual Address Descriptor) vol -f image.raw windows.vadinfo.VadInfo --pid 1234
WINDOWS PLUGINS - REGISTRY ANALYSIS#
# List registry hives vol -f image.raw windows.registry.hivelist.HiveList # Print registry key vol -f image.raw windows.registry.printkey.PrintKey --key "Software\Microsoft\Windows\CurrentVersion\Run" # Dump specific hive vol -f image.raw windows.registry.hivelist.HiveList --dump # Common persistence keys to check: # HKLM\Software\Microsoft\Windows\CurrentVersion\Run # HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce # HKCU\Software\Microsoft\Windows\CurrentVersion\Run # HKLM\System\CurrentControlSet\Services # HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon # User assist (program execution evidence) vol -f image.raw windows.registry.userassist.UserAssist
WINDOWS PLUGINS - FILE AND MEMORY#
# Scan for file objects vol -f image.raw windows.filescan.FileScan # Dump a file from memory vol -f image.raw windows.dumpfiles.DumpFiles --virtaddr 0xfa8001234560 vol -f image.raw windows.dumpfiles.DumpFiles --pid 1234 # Memory map of a process vol -f image.raw windows.memmap.Memmap --pid 1234 --dump # Pool scanner for various objects vol -f image.raw windows.poolscanner.PoolScanner # Search for strings in process memory vol -f image.raw windows.strings.Strings --strings-file strings.txt
WINDOWS PLUGINS - ADDITIONAL#
# Services vol -f image.raw windows.svcscan.SvcScan # Scheduled tasks vol -f image.raw windows.scheduled_tasks.ScheduledTasks # Clipboard contents vol -f image.raw windows.clipboard.ClipBoard # Windows event logs from memory vol -f image.raw windows.evtlogs.EvtLogs # MFT (Master File Table) entries vol -f image.raw windows.mftscan.MFTScan # Cached credentials vol -f image.raw windows.hashdump.Hashdump vol -f image.raw windows.lsadump.Lsadump vol -f image.raw windows.cachedump.Cachedump
LINUX PLUGINS#
# Process listing vol -f image.lime linux.pslist.PsList vol -f image.lime linux.pstree.PsTree vol -f image.lime linux.psaux.PsAux # Bash history from memory vol -f image.lime linux.bash.Bash # Network connections vol -f image.lime linux.sockstat.Sockstat # Loaded kernel modules vol -f image.lime linux.lsmod.Lsmod # Open files vol -f image.lime linux.lsof.Lsof # Mount points vol -f image.lime linux.mountinfo.MountInfo # Environment variables vol -f image.lime linux.envars.Envars # Detect rootkits (check syscall table) vol -f image.lime linux.check_syscall.Check_syscall vol -f image.lime linux.check_modules.Check_modules vol -f image.lime linux.hidden_modules.Hidden_modules vol -f image.lime linux.check_idt.Check_idt # ELF file detection in memory vol -f image.lime linux.elfs.Elfs # Capabilities vol -f image.lime linux.capabilities.Capabilities # Process maps vol -f image.lime linux.proc.Maps --pid 1234
ANALYSIS WORKFLOW#
1. INITIAL TRIAGE vol -f image.raw windows.info.Info vol -f image.raw windows.pslist.PsList vol -f image.raw windows.pstree.PsTree vol -f image.raw windows.netscan.NetScan 2. IDENTIFY SUSPICIOUS PROCESSES - Unusual parent-child relationships (e.g., Word spawning cmd.exe) - Processes with misspelled names (svchost vs svchsot) - Processes running from unusual paths (\Temp, \AppData) - Multiple instances where only one should exist - Processes with network connections that shouldn't have them 3. DEEP DIVE ON SUSPICIOUS PROCESSES vol -f image.raw windows.cmdline.CmdLine --pid <PID> vol -f image.raw windows.dlllist.DllList --pid <PID> vol -f image.raw windows.handles.Handles --pid <PID> vol -f image.raw windows.malfind.Malfind --pid <PID> vol -f image.raw windows.memmap.Memmap --pid <PID> --dump 4. CHECK FOR PERSISTENCE vol -f image.raw windows.svcscan.SvcScan vol -f image.raw windows.registry.printkey.PrintKey --key "Software\Microsoft\Windows\CurrentVersion\Run" 5. EXTRACT ARTIFACTS vol -f image.raw windows.dumpfiles.DumpFiles --pid <PID> vol -f image.raw windows.pslist.PsList --pid <PID> --dump 6. CORRELATE WITH OTHER EVIDENCE - Cross-reference with network logs - Compare with disk forensics timeline - Check IOCs against threat intel feeds
COMMON MALWARE INDICATORS IN MEMORY#
Process anomalies: - svchost.exe not spawned by services.exe - lsass.exe with parent other than wininit.exe - Multiple lsass.exe instances - csrss.exe spawned by anything other than smss.exe - explorer.exe with parent other than userinit.exe - Processes with no parent (orphaned) Memory anomalies: - PAGE_EXECUTE_READWRITE sections with PE headers (malfind) - Injected DLLs not on disk - Hollow processes (image path differs from in-memory image) - Unusual VAD tags Network anomalies: - Beaconing patterns (regular interval connections) - Connections to TOR exit nodes - DNS queries to DGA domains - C2 on common ports (80, 443) from non-browser processes
OUTPUT AND REPORTING#
# Output to CSV vol -f image.raw windows.pslist.PsList -r csv > processes.csv # Output to JSON vol -f image.raw windows.pslist.PsList -r json > processes.json # Render as text (pretty print) vol -f image.raw windows.pslist.PsList -r pretty # Specify output directory for dumps vol -f image.raw -o /evidence/dumps/ windows.malfind.Malfind --dump
REFERENCES#
- Volatility 3 Documentation: https://volatility3.readthedocs.io/ - Volatility 3 GitHub: https://github.com/volatilityfoundation/volatility3 - SANS Memory Forensics Cheat Sheet (Hal Pomeranz) - The Art of Memory Forensics (Ligh, Case, Levy, Walters) - MemProcFS: https://github.com/ufrisk/MemProcFS
MEMORY FORENSICS WITH VOLATILITY 3
=====================================
Source: https://cheatsheet.johlem.net
Complete guide to memory acquisition, analysis, and forensic
investigation using Volatility 3 and supporting tools.
MEMORY ACQUISITION TOOLS
--------------------------
Windows:
WinPmem:
winpmem_mini_x64.exe output.raw
winpmem_mini_x64.exe output.aff4 # AFF4 format
DumpIt (Comae):
DumpIt.exe # interactive, creates .dmp
DumpIt.exe /OUTPUT dump.raw /QUIET # non-interactive
FTK Imager:
File > Capture Memory > select output path
Belkasoft RAM Capturer:
GUI-based, minimal footprint
Magnet RAM Capture:
Free tool, simple GUI
Linux:
LiME (Linux Memory Extractor):
insmod lime.ko "path=/evidence/mem.lime format=lime"
insmod lime.ko "path=/evidence/mem.raw format=raw"
insmod lime.ko "path=tcp:4444 format=lime" # remote acquisition
AVML (Microsoft):
./avml /evidence/memory.lime
./avml --compress /evidence/memory.lime.compressed
/proc/kcore:
dd if=/proc/kcore of=/evidence/kcore bs=1M # not always reliable
fmem:
dd if=/dev/fmem of=/evidence/mem.raw bs=1M
macOS:
osxpmem:
sudo osxpmem -o /evidence/mem.aff4
sudo osxpmem --format raw -o /evidence/mem.raw
Virtual Machines:
VMware: .vmem file in VM directory (suspend VM first)
VirtualBox: vboxmanage debugvm <vm> dumpvmcore --filename mem.elf
Hyper-V: Checkpoint creates .bin memory files
QEMU/KVM: virsh dump <domain> mem.raw --memory-only
VOLATILITY 3 INSTALLATION
---------------------------
# Install from pip
pip3 install volatility3
# Install from source
git clone https://github.com/volatilityfoundation/volatility3.git
cd volatility3
pip3 install -r requirements.txt
python3 vol.py -h
# Install symbol tables (ISF)
# Windows symbols download automatically
# Linux: need to generate from kernel debug symbols
# Place in volatility3/symbols/ directory
# Basic syntax
vol -f <memory_image> <plugin>
python3 vol.py -f <memory_image> <plugin>
# List available plugins
vol -f image.raw --help
PROFILE DETECTION AND IMAGE INFO
----------------------------------
# Volatility 3 auto-detects OS (no manual profile needed)
# To see image info:
vol -f image.raw banners.Banners
vol -f image.raw windows.info.Info
vol -f image.raw linux.bash.Bash
# If auto-detection fails, specify the OS:
vol -f image.raw -o "output/" windows.pslist.PsList
WINDOWS PLUGINS - PROCESS ANALYSIS
-------------------------------------
# List running processes
vol -f image.raw windows.pslist.PsList
vol -f image.raw windows.pslist.PsList --pid 1234
# Process tree (parent-child relationships)
vol -f image.raw windows.pstree.PsTree
# Scan for hidden/terminated processes (pool scanner)
vol -f image.raw windows.psscan.PsScan
# Compare pslist vs psscan to find hidden processes
# Processes in psscan but not pslist may be hidden by rootkit
# Process command line arguments
vol -f image.raw windows.cmdline.CmdLine
vol -f image.raw windows.cmdline.CmdLine --pid 1234
# Process environment variables
vol -f image.raw windows.envars.Envars
vol -f image.raw windows.envars.Envars --pid 1234
# Dump process executable
vol -f image.raw windows.pslist.PsList --pid 1234 --dump
WINDOWS PLUGINS - DLL AND HANDLE ANALYSIS
-------------------------------------------
# List loaded DLLs per process
vol -f image.raw windows.dlllist.DllList
vol -f image.raw windows.dlllist.DllList --pid 1234
# List process handles (files, registry, mutexes)
vol -f image.raw windows.handles.Handles
vol -f image.raw windows.handles.Handles --pid 1234
# Filter handles by type
vol -f image.raw windows.handles.Handles --pid 1234 --type File
vol -f image.raw windows.handles.Handles --pid 1234 --type Key
vol -f image.raw windows.handles.Handles --pid 1234 --type Mutant
# SIDs associated with processes
vol -f image.raw windows.getsids.GetSIDs
# Privileges for processes
vol -f image.raw windows.privileges.Privs
vol -f image.raw windows.privileges.Privs --pid 1234
WINDOWS PLUGINS - NETWORK ANALYSIS
-------------------------------------
# Network connections and listening sockets
vol -f image.raw windows.netscan.NetScan
vol -f image.raw windows.netstat.NetStat
# Key fields: Owner (process), LocalAddr, ForeignAddr, State, Proto
# Look for:
# - Connections to known bad IPs
# - Unusual ports (4444, 5555, 8080 from non-web processes)
# - Processes that shouldn't have network connections
# - Connections in ESTABLISHED state to external IPs
WINDOWS PLUGINS - MALWARE DETECTION
--------------------------------------
# Detect injected code / hollowed processes
vol -f image.raw windows.malfind.Malfind
vol -f image.raw windows.malfind.Malfind --pid 1234
# Looks for: PAGE_EXECUTE_READWRITE memory regions with MZ headers
# Dumps suspicious memory sections automatically
# Detect API hooks (IAT/EAT/Inline)
vol -f image.raw windows.ssdt.SSDT
# Checks System Service Descriptor Table for hooks
# Loaded kernel modules
vol -f image.raw windows.modules.Modules
vol -f image.raw windows.modscan.ModScan
# Driver analysis
vol -f image.raw windows.driverscan.DriverScan
vol -f image.raw windows.driverirp.DriverIrp
# Detect code injection via VAD (Virtual Address Descriptor)
vol -f image.raw windows.vadinfo.VadInfo --pid 1234
WINDOWS PLUGINS - REGISTRY ANALYSIS
--------------------------------------
# List registry hives
vol -f image.raw windows.registry.hivelist.HiveList
# Print registry key
vol -f image.raw windows.registry.printkey.PrintKey --key "Software\Microsoft\Windows\CurrentVersion\Run"
# Dump specific hive
vol -f image.raw windows.registry.hivelist.HiveList --dump
# Common persistence keys to check:
# HKLM\Software\Microsoft\Windows\CurrentVersion\Run
# HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
# HKCU\Software\Microsoft\Windows\CurrentVersion\Run
# HKLM\System\CurrentControlSet\Services
# HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
# User assist (program execution evidence)
vol -f image.raw windows.registry.userassist.UserAssist
WINDOWS PLUGINS - FILE AND MEMORY
------------------------------------
# Scan for file objects
vol -f image.raw windows.filescan.FileScan
# Dump a file from memory
vol -f image.raw windows.dumpfiles.DumpFiles --virtaddr 0xfa8001234560
vol -f image.raw windows.dumpfiles.DumpFiles --pid 1234
# Memory map of a process
vol -f image.raw windows.memmap.Memmap --pid 1234 --dump
# Pool scanner for various objects
vol -f image.raw windows.poolscanner.PoolScanner
# Search for strings in process memory
vol -f image.raw windows.strings.Strings --strings-file strings.txt
WINDOWS PLUGINS - ADDITIONAL
------------------------------
# Services
vol -f image.raw windows.svcscan.SvcScan
# Scheduled tasks
vol -f image.raw windows.scheduled_tasks.ScheduledTasks
# Clipboard contents
vol -f image.raw windows.clipboard.ClipBoard
# Windows event logs from memory
vol -f image.raw windows.evtlogs.EvtLogs
# MFT (Master File Table) entries
vol -f image.raw windows.mftscan.MFTScan
# Cached credentials
vol -f image.raw windows.hashdump.Hashdump
vol -f image.raw windows.lsadump.Lsadump
vol -f image.raw windows.cachedump.Cachedump
LINUX PLUGINS
--------------
# Process listing
vol -f image.lime linux.pslist.PsList
vol -f image.lime linux.pstree.PsTree
vol -f image.lime linux.psaux.PsAux
# Bash history from memory
vol -f image.lime linux.bash.Bash
# Network connections
vol -f image.lime linux.sockstat.Sockstat
# Loaded kernel modules
vol -f image.lime linux.lsmod.Lsmod
# Open files
vol -f image.lime linux.lsof.Lsof
# Mount points
vol -f image.lime linux.mountinfo.MountInfo
# Environment variables
vol -f image.lime linux.envars.Envars
# Detect rootkits (check syscall table)
vol -f image.lime linux.check_syscall.Check_syscall
vol -f image.lime linux.check_modules.Check_modules
vol -f image.lime linux.hidden_modules.Hidden_modules
vol -f image.lime linux.check_idt.Check_idt
# ELF file detection in memory
vol -f image.lime linux.elfs.Elfs
# Capabilities
vol -f image.lime linux.capabilities.Capabilities
# Process maps
vol -f image.lime linux.proc.Maps --pid 1234
ANALYSIS WORKFLOW
------------------
1. INITIAL TRIAGE
vol -f image.raw windows.info.Info
vol -f image.raw windows.pslist.PsList
vol -f image.raw windows.pstree.PsTree
vol -f image.raw windows.netscan.NetScan
2. IDENTIFY SUSPICIOUS PROCESSES
- Unusual parent-child relationships (e.g., Word spawning cmd.exe)
- Processes with misspelled names (svchost vs svchsot)
- Processes running from unusual paths (\Temp, \AppData)
- Multiple instances where only one should exist
- Processes with network connections that shouldn't have them
3. DEEP DIVE ON SUSPICIOUS PROCESSES
vol -f image.raw windows.cmdline.CmdLine --pid <PID>
vol -f image.raw windows.dlllist.DllList --pid <PID>
vol -f image.raw windows.handles.Handles --pid <PID>
vol -f image.raw windows.malfind.Malfind --pid <PID>
vol -f image.raw windows.memmap.Memmap --pid <PID> --dump
4. CHECK FOR PERSISTENCE
vol -f image.raw windows.svcscan.SvcScan
vol -f image.raw windows.registry.printkey.PrintKey --key "Software\Microsoft\Windows\CurrentVersion\Run"
5. EXTRACT ARTIFACTS
vol -f image.raw windows.dumpfiles.DumpFiles --pid <PID>
vol -f image.raw windows.pslist.PsList --pid <PID> --dump
6. CORRELATE WITH OTHER EVIDENCE
- Cross-reference with network logs
- Compare with disk forensics timeline
- Check IOCs against threat intel feeds
COMMON MALWARE INDICATORS IN MEMORY
--------------------------------------
Process anomalies:
- svchost.exe not spawned by services.exe
- lsass.exe with parent other than wininit.exe
- Multiple lsass.exe instances
- csrss.exe spawned by anything other than smss.exe
- explorer.exe with parent other than userinit.exe
- Processes with no parent (orphaned)
Memory anomalies:
- PAGE_EXECUTE_READWRITE sections with PE headers (malfind)
- Injected DLLs not on disk
- Hollow processes (image path differs from in-memory image)
- Unusual VAD tags
Network anomalies:
- Beaconing patterns (regular interval connections)
- Connections to TOR exit nodes
- DNS queries to DGA domains
- C2 on common ports (80, 443) from non-browser processes
OUTPUT AND REPORTING
---------------------
# Output to CSV
vol -f image.raw windows.pslist.PsList -r csv > processes.csv
# Output to JSON
vol -f image.raw windows.pslist.PsList -r json > processes.json
# Render as text (pretty print)
vol -f image.raw windows.pslist.PsList -r pretty
# Specify output directory for dumps
vol -f image.raw -o /evidence/dumps/ windows.malfind.Malfind --dump
REFERENCES
----------
- Volatility 3 Documentation: https://volatility3.readthedocs.io/
- Volatility 3 GitHub: https://github.com/volatilityfoundation/volatility3
- SANS Memory Forensics Cheat Sheet (Hal Pomeranz)
- The Art of Memory Forensics (Ligh, Case, Levy, Walters)
- MemProcFS: https://github.com/ufrisk/MemProcFS
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.