Forensics
Volatility 3
Memory forensics framework for RAM dumps.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Analyzing memory images for malware, credentials, or incident response.
How
Identify OS; run pslist, netscan, malfind, etc.
Why
Memory is a goldmine for IR and offensive artifact understanding.
Commands & usage
vol -f memory.dmp windows.info
vol -f memory.dmp windows.pslist
vol -f memory.dmp windows.netscan
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Forensics
Autopsy
GUI digital forensics platform on The Sleuth Kit.
The Sleuth Kit
CLI tools for disk image forensic analysis.
Wireshark / tshark
World-class packet capture and protocol analysis tool.
tcpdump
CLI packet capture utility.
ExifTool
Read/write metadata in files (images, docs, etc.).
steghide / zsteg / steghide tools
Steganography detection and extraction tools for CTFs and investigations.