memory-forensics
wshobson/agents
Acquire and analyze memory dumps using Volatility to detect malware, extract artifacts, and investigate incidents.
What is memory-forensics?
Master memory forensics techniques for analyzing RAM captures from Windows, Linux, and macOS systems. Use this skill when performing incident response, malware analysis, or extracting volatile artifacts like processes, credentials, and injected code before system shutdown.
- Acquire live memory from Windows (WinPmem, DumpIt), Linux (LiME), and macOS (osxpmem) systems
- Extract and analyze process trees, network connections, and DLL dependencies using Volatility 3
- Detect process injection, rootkits, and code anomalies via malfind, VAD analysis, and YARA scanning
- Recover credentials, cached domain data, and LSA secrets from process memory
- Generate forensic timelines and identify persistence mechanisms (registry, services, scheduled tasks)
- Scan memory with custom YARA rules and extract obfuscated strings using FLOSS
How to install memory-forensics
npx skills add https://github.com/wshobson/agents --skill memory-forensics- Volatility 3 framework installed
- Memory acquisition tool appropriate for target OS (WinPmem, LiME, osxpmem, etc.)
- Raw or ELF format memory dump file
- Optional: YARA rules for pattern matching and FLOSS for obfuscated string extraction
How to use memory-forensics
- 1.Acquire memory dump using appropriate tool for the target system (WinPmem for Windows, LiME for Linux, osxpmem for macOS)
- 2.Hash the memory dump immediately and document acquisition metadata for chain of custody
- 3.Run initial process survey with vol windows.pstree and vol windows.pslist to identify running processes
- 4.Execute targeted analysis workflows: malware analysis (malfind, dlllist, handles) or incident response (timeliner, cmdline, registry)
- 5.Dump suspicious executables and scan with YARA rules or extract strings for IOC identification
- 6.Cross-reference findings across multiple plugins and correlate with disk/network forensics for complete picture
Use cases
- Analyze a memory dump during breach investigation to identify running malware and lateral movement
- Detect process injection techniques (DLL injection, process hollowing, APC injection) in a suspected compromised system
- Extract credentials and browser session data from memory to understand attacker access scope
- Identify rootkits and hidden processes by comparing pslist vs psscan output
- Acquire volatile memory from a live system before shutdown to preserve evidence of active threats
- Incident response analysts investigating active breaches
- Malware analysts examining suspicious processes and injected code
- Forensic investigators performing post-incident analysis
- Security researchers studying rootkits and advanced evasion techniques
- SOC teams triaging memory dumps during incident triage
memory-forensics FAQ
pslist walks the kernel's doubly-linked list of active processes and may miss hidden processes removed via DKOM. psscan scans physical memory for EPROCESS structures and can find processes hidden by rootkits. Compare both outputs to detect process hiding.
Use vol windows.malfind to identify suspicious memory regions with PAGE_EXECUTE_READWRITE protection or MZ headers in non-image VADs. Analyze VAD (Virtual Address Descriptor) structures, check for mismatched process lists, and examine injected code patterns.
Yes. Use vol windows.hashdump for NTLM hashes, vol windows.lsadump for LSA secrets, and vol windows.cachedump for cached domain credentials. These require proper privilege levels and may depend on OS version and memory state.
For Windows, use WinPmem (recommended, lightweight). For Linux, use LiME (Linux Memory Extractor). For macOS, use osxpmem. For VMs, use native snapshots (VMware .vmem, VirtualBox checkpoints, QEMU virsh dump).
Define strings (hex patterns, ASCII, wide strings) and conditions to match. Common patterns include MZ headers, shellcode prologues, and API call sequences. Scan with vol windows.yarascan --yara-rules rules.yar to find matches in process or kernel memory.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: memory-forensics description: Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.
Memory Forensics
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.
When to Use This Skill
- Performing memory analysis during incident response or breach investigation
- Extracting malware artifacts (processes, injected code, network connections) from a RAM capture
- Acquiring volatile memory from a live Windows/Linux/macOS system before shutdown
- Using Volatility 3 / Rekall to triage memory dumps
- Recovering credentials, browser sessions, or open files from process memory
Memory Acquisition
Live Acquisition Tools
Windows
# WinPmem (Recommended)
winpmem_mini_x64.exe memory.raw
# DumpIt
DumpIt.exe
# Belkasoft RAM Capturer
# GUI-based, outputs raw format
# Magnet RAM Capture
# GUI-based, outputs raw format
Linux
# LiME (Linux Memory Extractor)
sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)
sudo dd if=/dev/mem of=memory.raw bs=1M
# /proc/kcore (ELF format)
sudo cp /proc/kcore memory.elf
macOS
# osxpmem
sudo ./osxpmem -o memory.raw
# MacQuisition (commercial)
Virtual Machine Memory
# VMware: .vmem file is raw memory
cp vm.vmem memory.raw
# VirtualBox: Use debug console
vboxmanage debugvm "VMName" dumpvmcore --filename memory.elf
# QEMU
virsh dump <domain> memory.raw --memory-only
# Hyper-V
# Checkpoint contains memory state
Detailed section: Volatility 3 Framework
Originally a 2680-byte section in this SKILL.md. Moved to references/details.md to fit Codex's 8 KB skill body cap.
Analysis Workflows
Malware Analysis Workflow
# 1. Initial process survey
vol -f memory.raw windows.pstree > processes.txt
vol -f memory.raw windows.pslist > pslist.txt
# 2. Network connections
vol -f memory.raw windows.netscan > network.txt
# 3. Detect injection
vol -f memory.raw windows.malfind > malfind.txt
# 4. Analyze suspicious processes
vol -f memory.raw windows.dlllist --pid <PID>
vol -f memory.raw windows.handles --pid <PID>
# 5. Dump suspicious executables
vol -f memory.raw windows.pslist --pid <PID> --dump
# 6. Extract strings from dumps
strings -a pid.<PID>.exe > strings.txt
# 7. YARA scanning
vol -f memory.raw windows.yarascan --yara-rules malware.yar
Incident Response Workflow
# 1. Timeline of events
vol -f memory.raw windows.timeliner > timeline.csv
# 2. User activity
vol -f memory.raw windows.cmdline
vol -f memory.raw windows.consoles
# 3. Persistence mechanisms
vol -f memory.raw windows.registry.printkey \
--key "Software\Microsoft\Windows\CurrentVersion\Run"
# 4. Services
vol -f memory.raw windows.svcscan
# 5. Scheduled tasks
vol -f memory.raw windows.scheduled_tasks
# 6. Recent files
vol -f memory.raw windows.filescan | grep -i "recent"
Data Structures
Windows Process Structures
// EPROCESS (Executive Process)
typedef struct _EPROCESS {
KPROCESS Pcb; // Kernel process block
EX_PUSH_LOCK ProcessLock;
LARGE_INTEGER CreateTime;
LARGE_INTEGER ExitTime;
// ...
LIST_ENTRY ActiveProcessLinks; // Doubly-linked list
ULONG_PTR UniqueProcessId; // PID
// ...
PEB* Peb; // Process Environment Block
// ...
} EPROCESS;
// PEB (Process Environment Block)
typedef struct _PEB {
BOOLEAN InheritedAddressSpace;
BOOLEAN ReadImageFileExecOptions;
BOOLEAN BeingDebugged; // Anti-debug check
// ...
PVOID ImageBaseAddress; // Base address of executable
PPEB_LDR_DATA Ldr; // Loader data (DLL list)
PRTL_USER_PROCESS_PARAMETERS ProcessParameters;
// ...
} PEB;
VAD (Virtual Address Descriptor)
typedef struct _MMVAD {
MMVAD_SHORT Core;
union {
ULONG LongFlags;
MMVAD_FLAGS VadFlags;
} u;
// ...
PVOID FirstPrototypePte;
PVOID LastContiguousPte;
// ...
PFILE_OBJECT FileObject;
} MMVAD;
// Memory protection flags
#define PAGE_EXECUTE 0x10
#define PAGE_EXECUTE_READ 0x20
#define PAGE_EXECUTE_READWRITE 0x40
#define PAGE_EXECUTE_WRITECOPY 0x80
Detection Patterns
Process Injection Indicators
# Malfind indicators
# - PAGE_EXECUTE_READWRITE protection (suspicious)
# - MZ header in non-image VAD region
# - Shellcode patterns at allocation start
# Common injection techniques
# 1. Classic DLL Injection
# - VirtualAllocEx + WriteProcessMemory + CreateRemoteThread
# 2. Process Hollowing
# - CreateProcess (SUSPENDED) + NtUnmapViewOfSection + WriteProcessMemory
# 3. APC Injection
# - QueueUserAPC targeting alertable threads
# 4. Thread Execution Hijacking
# - SuspendThread + SetThreadContext + ResumeThread
Rootkit Detection
# Compare process lists
vol -f memory.raw windows.pslist > pslist.txt
vol -f memory.raw windows.psscan > psscan.txt
diff pslist.txt psscan.txt # Hidden processes
# Check for DKOM (Direct Kernel Object Manipulation)
vol -f memory.raw windows.callbacks
# Detect hooked functions
vol -f memory.raw windows.ssdt # System Service Descriptor Table
# Driver analysis
vol -f memory.raw windows.driverscan
vol -f memory.raw windows.driverirp
Credential Extraction
# Dump hashes (requires hivelist first)
vol -f memory.raw windows.hashdump
# LSA secrets
vol -f memory.raw windows.lsadump
# Cached domain credentials
vol -f memory.raw windows.cachedump
# Mimikatz-style extraction
# Requires specific plugins/tools
YARA Integration
Writing Memory YARA Rules
rule Suspicious_Injection
{
meta:
description = "Detects common injection shellcode"
strings:
// Common shellcode patterns
$mz = { 4D 5A }
$shellcode1 = { 55 8B EC 83 EC } // Function prologue
$api_hash = { 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 } // Push hash, call
condition:
$mz at 0 or any of ($shellcode*)
}
rule Cobalt_Strike_Beacon
{
meta:
description = "Detects Cobalt Strike beacon in memory"
strings:
$config = { 00 01 00 01 00 02 }
$sleep = "sleeptime"
$beacon = "%s (admin)" wide
condition:
2 of them
}
Scanning Memory
# Scan all process memory
vol -f memory.raw windows.yarascan --yara-rules rules.yar
# Scan specific process
vol -f memory.raw windows.yarascan --yara-rules rules.yar --pid 1234
# Scan kernel memory
vol -f memory.raw windows.yarascan --yara-rules rules.yar --kernel
String Analysis
Extracting Strings
# Basic string extraction
strings -a memory.raw > all_strings.txt
# Unicode strings
strings -el memory.raw >> all_strings.txt
# Targeted extraction from process dump
vol -f memory.raw windows.memmap --pid 1234 --dump
strings -a pid.1234.dmp > process_strings.txt
# Pattern matching
grep -E "(https?://|[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})" all_strings.txt
FLOSS for Obfuscated Strings
# FLOSS extracts obfuscated strings
floss malware.exe > floss_output.txt
# From memory dump
floss pid.1234.dmp
Best Practices
Acquisition Best Practices
- Minimize footprint: Use lightweight acquisition tools
- Document everything: Record time, tool, and hash of capture
- Verify integrity: Hash memory dump immediately after capture
- Chain of custody: Maintain proper forensic handling
Analysis Best Practices
- Start broad: Get overview before deep diving
- Cross-reference: Use multiple plugins for same data
- Timeline correlation: Correlate memory findings with disk/network
- Document findings: Keep detailed notes and screenshots
- Validate results: Verify findings through multiple methods
Common Pitfalls
- Stale data: Memory is volatile, analyze promptly
- Incomplete dumps: Verify dump size matches expected RAM
- Symbol issues: Ensure correct symbol files for OS version
- Smear: Memory may change during acquisition
- Encryption: Some data may be encrypted in memory
Related skills
More from wshobson/agents and the wider catalog.

memory-safety-patterns
Cross-language RAII, ownership, and smart pointer patterns for memory-safe Rust, C++, and C code.

microservices-patterns
Design distributed systems with service boundaries, event-driven communication, and resilience patterns.

ml-pipeline-workflow
Build end-to-end MLOps pipelines from data preparation through model training, validation, and production deployment.

mobile-android-design
Master Material Design 3 and Jetpack Compose for modern Android app interfaces.

mobile-ios-design
Master iOS HIG and SwiftUI patterns for native Apple app design.

modern-javascript-patterns
Master ES6+ features and modern JavaScript patterns for clean, efficient code.