内存转储分析
原名:analyzing-memory-dumps-with-volatility
使用 Volatility 框架分析受损系统的 RAM 内存转储,以识别恶意进程。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-18
- TRACE 评分
- 3.2 / 5
内容概览
- A compromised system's RAM has been captured and needs forensic analysis for malware artifacts - Detecting fileless malware that exists only in memory without persistent disk artifacts - Extracting encryption keys, passwords, or decrypted configuration from process memory - Identifying process injection, DLL injection, or process hollowing in a compromised system - Analyzing rootkit activity that hides from standard disk-based forensic tools Do not use for disk image analysis; use Autopsy, FTK, or Sleuth Kit for disk forensics. - Volatility 3 installed (pip install volatility3) with symbol tables for target OS - Memory dump file acquired from the target system (using WinPmem, LiME, or DumpIt) - Knowledge of the source OS version for correct profile/symbol selection - Sufficient disk space (memory dumps can be 4-64 GB) - YARA rules for scanning memory for known malware signatures - Stri…