← All cheat sheets

MEMORY FORENSICS WITH VOLATILITY 3

Plain-text reference · 11 KB. Read it, search it (Ctrl-F) or print it.

Complete guide to memory acquisition, analysis, and forensic
investigation using Volatility 3 and supporting tools.

MEMORY ACQUISITION TOOLS#

Windows:
  WinPmem:
    winpmem_mini_x64.exe output.raw
    winpmem_mini_x64.exe output.aff4         # AFF4 format

  DumpIt (Comae):
    DumpIt.exe                                # interactive, creates .dmp
    DumpIt.exe /OUTPUT dump.raw /QUIET        # non-interactive

  FTK Imager:
    File > Capture Memory > select output path

  Belkasoft RAM Capturer:
    GUI-based, minimal footprint

  Magnet RAM Capture:
    Free tool, simple GUI

Linux:
  LiME (Linux Memory Extractor):
    insmod lime.ko "path=/evidence/mem.lime format=lime"
    insmod lime.ko "path=/evidence/mem.raw format=raw"
    insmod lime.ko "path=tcp:4444 format=lime"   # remote acquisition

  AVML (Microsoft):
    ./avml /evidence/memory.lime
    ./avml --compress /evidence/memory.lime.compressed

  /proc/kcore:
    dd if=/proc/kcore of=/evidence/kcore bs=1M   # not always reliable

  fmem:
    dd if=/dev/fmem of=/evidence/mem.raw bs=1M

macOS:
  osxpmem:
    sudo osxpmem -o /evidence/mem.aff4
    sudo osxpmem --format raw -o /evidence/mem.raw

Virtual Machines:
  VMware:  .vmem file in VM directory (suspend VM first)
  VirtualBox: vboxmanage debugvm <vm> dumpvmcore --filename mem.elf
  Hyper-V: Checkpoint creates .bin memory files
  QEMU/KVM: virsh dump <domain> mem.raw --memory-only

VOLATILITY 3 INSTALLATION#

# Install from pip
pip3 install volatility3

# Install from source
git clone https://github.com/volatilityfoundation/volatility3.git
cd volatility3
pip3 install -r requirements.txt
python3 vol.py -h

# Install symbol tables (ISF)
# Windows symbols download automatically
# Linux: need to generate from kernel debug symbols
# Place in volatility3/symbols/ directory

# Basic syntax
vol -f <memory_image> <plugin>
python3 vol.py -f <memory_image> <plugin>

# List available plugins
vol -f image.raw --help

PROFILE DETECTION AND IMAGE INFO#

# Volatility 3 auto-detects OS (no manual profile needed)
# To see image info:
vol -f image.raw banners.Banners
vol -f image.raw windows.info.Info
vol -f image.raw linux.bash.Bash

# If auto-detection fails, specify the OS:
vol -f image.raw -o "output/" windows.pslist.PsList

WINDOWS PLUGINS - PROCESS ANALYSIS#

# List running processes
vol -f image.raw windows.pslist.PsList
vol -f image.raw windows.pslist.PsList --pid 1234

# Process tree (parent-child relationships)
vol -f image.raw windows.pstree.PsTree

# Scan for hidden/terminated processes (pool scanner)
vol -f image.raw windows.psscan.PsScan

# Compare pslist vs psscan to find hidden processes
# Processes in psscan but not pslist may be hidden by rootkit

# Process command line arguments
vol -f image.raw windows.cmdline.CmdLine
vol -f image.raw windows.cmdline.CmdLine --pid 1234

# Process environment variables
vol -f image.raw windows.envars.Envars
vol -f image.raw windows.envars.Envars --pid 1234

# Dump process executable
vol -f image.raw windows.pslist.PsList --pid 1234 --dump

WINDOWS PLUGINS - DLL AND HANDLE ANALYSIS#

# List loaded DLLs per process
vol -f image.raw windows.dlllist.DllList
vol -f image.raw windows.dlllist.DllList --pid 1234

# List process handles (files, registry, mutexes)
vol -f image.raw windows.handles.Handles
vol -f image.raw windows.handles.Handles --pid 1234

# Filter handles by type
vol -f image.raw windows.handles.Handles --pid 1234 --type File
vol -f image.raw windows.handles.Handles --pid 1234 --type Key
vol -f image.raw windows.handles.Handles --pid 1234 --type Mutant

# SIDs associated with processes
vol -f image.raw windows.getsids.GetSIDs

# Privileges for processes
vol -f image.raw windows.privileges.Privs
vol -f image.raw windows.privileges.Privs --pid 1234

WINDOWS PLUGINS - NETWORK ANALYSIS#

# Network connections and listening sockets
vol -f image.raw windows.netscan.NetScan
vol -f image.raw windows.netstat.NetStat

# Key fields: Owner (process), LocalAddr, ForeignAddr, State, Proto
# Look for:
#   - Connections to known bad IPs
#   - Unusual ports (4444, 5555, 8080 from non-web processes)
#   - Processes that shouldn't have network connections
#   - Connections in ESTABLISHED state to external IPs

WINDOWS PLUGINS - MALWARE DETECTION#

# Detect injected code / hollowed processes
vol -f image.raw windows.malfind.Malfind
vol -f image.raw windows.malfind.Malfind --pid 1234
# Looks for: PAGE_EXECUTE_READWRITE memory regions with MZ headers
# Dumps suspicious memory sections automatically

# Detect API hooks (IAT/EAT/Inline)
vol -f image.raw windows.ssdt.SSDT
# Checks System Service Descriptor Table for hooks

# Loaded kernel modules
vol -f image.raw windows.modules.Modules
vol -f image.raw windows.modscan.ModScan

# Driver analysis
vol -f image.raw windows.driverscan.DriverScan
vol -f image.raw windows.driverirp.DriverIrp

# Detect code injection via VAD (Virtual Address Descriptor)
vol -f image.raw windows.vadinfo.VadInfo --pid 1234

WINDOWS PLUGINS - REGISTRY ANALYSIS#

# List registry hives
vol -f image.raw windows.registry.hivelist.HiveList

# Print registry key
vol -f image.raw windows.registry.printkey.PrintKey --key "Software\Microsoft\Windows\CurrentVersion\Run"

# Dump specific hive
vol -f image.raw windows.registry.hivelist.HiveList --dump

# Common persistence keys to check:
#   HKLM\Software\Microsoft\Windows\CurrentVersion\Run
#   HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
#   HKCU\Software\Microsoft\Windows\CurrentVersion\Run
#   HKLM\System\CurrentControlSet\Services
#   HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

# User assist (program execution evidence)
vol -f image.raw windows.registry.userassist.UserAssist

WINDOWS PLUGINS - FILE AND MEMORY#

# Scan for file objects
vol -f image.raw windows.filescan.FileScan

# Dump a file from memory
vol -f image.raw windows.dumpfiles.DumpFiles --virtaddr 0xfa8001234560
vol -f image.raw windows.dumpfiles.DumpFiles --pid 1234

# Memory map of a process
vol -f image.raw windows.memmap.Memmap --pid 1234 --dump

# Pool scanner for various objects
vol -f image.raw windows.poolscanner.PoolScanner

# Search for strings in process memory
vol -f image.raw windows.strings.Strings --strings-file strings.txt

WINDOWS PLUGINS - ADDITIONAL#

# Services
vol -f image.raw windows.svcscan.SvcScan

# Scheduled tasks
vol -f image.raw windows.scheduled_tasks.ScheduledTasks

# Clipboard contents
vol -f image.raw windows.clipboard.ClipBoard

# Windows event logs from memory
vol -f image.raw windows.evtlogs.EvtLogs

# MFT (Master File Table) entries
vol -f image.raw windows.mftscan.MFTScan

# Cached credentials
vol -f image.raw windows.hashdump.Hashdump
vol -f image.raw windows.lsadump.Lsadump
vol -f image.raw windows.cachedump.Cachedump

LINUX PLUGINS#

# Process listing
vol -f image.lime linux.pslist.PsList
vol -f image.lime linux.pstree.PsTree
vol -f image.lime linux.psaux.PsAux

# Bash history from memory
vol -f image.lime linux.bash.Bash

# Network connections
vol -f image.lime linux.sockstat.Sockstat

# Loaded kernel modules
vol -f image.lime linux.lsmod.Lsmod

# Open files
vol -f image.lime linux.lsof.Lsof

# Mount points
vol -f image.lime linux.mountinfo.MountInfo

# Environment variables
vol -f image.lime linux.envars.Envars

# Detect rootkits (check syscall table)
vol -f image.lime linux.check_syscall.Check_syscall
vol -f image.lime linux.check_modules.Check_modules
vol -f image.lime linux.hidden_modules.Hidden_modules
vol -f image.lime linux.check_idt.Check_idt

# ELF file detection in memory
vol -f image.lime linux.elfs.Elfs

# Capabilities
vol -f image.lime linux.capabilities.Capabilities

# Process maps
vol -f image.lime linux.proc.Maps --pid 1234

ANALYSIS WORKFLOW#

1. INITIAL TRIAGE
   vol -f image.raw windows.info.Info
   vol -f image.raw windows.pslist.PsList
   vol -f image.raw windows.pstree.PsTree
   vol -f image.raw windows.netscan.NetScan

2. IDENTIFY SUSPICIOUS PROCESSES
   - Unusual parent-child relationships (e.g., Word spawning cmd.exe)
   - Processes with misspelled names (svchost vs svchsot)
   - Processes running from unusual paths (\Temp, \AppData)
   - Multiple instances where only one should exist
   - Processes with network connections that shouldn't have them

3. DEEP DIVE ON SUSPICIOUS PROCESSES
   vol -f image.raw windows.cmdline.CmdLine --pid <PID>
   vol -f image.raw windows.dlllist.DllList --pid <PID>
   vol -f image.raw windows.handles.Handles --pid <PID>
   vol -f image.raw windows.malfind.Malfind --pid <PID>
   vol -f image.raw windows.memmap.Memmap --pid <PID> --dump

4. CHECK FOR PERSISTENCE
   vol -f image.raw windows.svcscan.SvcScan
   vol -f image.raw windows.registry.printkey.PrintKey --key "Software\Microsoft\Windows\CurrentVersion\Run"

5. EXTRACT ARTIFACTS
   vol -f image.raw windows.dumpfiles.DumpFiles --pid <PID>
   vol -f image.raw windows.pslist.PsList --pid <PID> --dump

6. CORRELATE WITH OTHER EVIDENCE
   - Cross-reference with network logs
   - Compare with disk forensics timeline
   - Check IOCs against threat intel feeds

COMMON MALWARE INDICATORS IN MEMORY#

Process anomalies:
  - svchost.exe not spawned by services.exe
  - lsass.exe with parent other than wininit.exe
  - Multiple lsass.exe instances
  - csrss.exe spawned by anything other than smss.exe
  - explorer.exe with parent other than userinit.exe
  - Processes with no parent (orphaned)

Memory anomalies:
  - PAGE_EXECUTE_READWRITE sections with PE headers (malfind)
  - Injected DLLs not on disk
  - Hollow processes (image path differs from in-memory image)
  - Unusual VAD tags

Network anomalies:
  - Beaconing patterns (regular interval connections)
  - Connections to TOR exit nodes
  - DNS queries to DGA domains
  - C2 on common ports (80, 443) from non-browser processes

OUTPUT AND REPORTING#

# Output to CSV
vol -f image.raw windows.pslist.PsList -r csv > processes.csv

# Output to JSON
vol -f image.raw windows.pslist.PsList -r json > processes.json

# Render as text (pretty print)
vol -f image.raw windows.pslist.PsList -r pretty

# Specify output directory for dumps
vol -f image.raw -o /evidence/dumps/ windows.malfind.Malfind --dump

REFERENCES#

- Volatility 3 Documentation: https://volatility3.readthedocs.io/
- Volatility 3 GitHub: https://github.com/volatilityfoundation/volatility3
- SANS Memory Forensics Cheat Sheet (Hal Pomeranz)
- The Art of Memory Forensics (Ligh, Case, Levy, Walters)
- MemProcFS: https://github.com/ufrisk/MemProcFS

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.