Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.
Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.
Memory Forensics
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.
When to Use This Skill
Performing memory analysis during incident response or breach investigation
Extracting malware artifacts (processes, injected code, network connections) from a RAM capture
Acquiring volatile memory from a live Windows/Linux/macOS system before shutdown
Using Volatility 3 / Rekall to triage memory dumps
Recovering credentials, browser sessions, or open files from process memory
Memory Acquisition
Live Acquisition Tools
Windows
# WinPmem (Recommended)
winpmem_mini_x64.exe memory.raw
# DumpIt
DumpIt.exe
# Belkasoft RAM Capturer
# GUI-based, outputs raw format
# Magnet RAM Capture
# GUI-based, outputs raw format
2 files · 11 KB8 KB
Install
It’s free, and every skill you add syncs into every AI tool on your computer, instantly.