内存转储分析

原名:analyzing-memory-dumps-with-volatility

使用 Volatility 框架分析受损系统的 RAM 内存转储,以识别恶意进程。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-18
TRACE 评分
3.2 / 5

内容概览

- A compromised system's RAM has been captured and needs forensic analysis for malware artifacts - Detecting fileless malware that exists only in memory without persistent disk artifacts - Extracting encryption keys, passwords, or decrypted configuration from process memory - Identifying process injection, DLL injection, or process hollowing in a compromised system - Analyzing rootkit activity that hides from standard disk-based forensic tools Do not use for disk image analysis; use Autopsy, FTK, or Sleuth Kit for disk forensics. - Volatility 3 installed (pip install volatility3) with symbol tables for target OS - Memory dump file acquired from the target system (using WinPmem, LiME, or DumpIt) - Knowledge of the source OS version for correct profile/symbol selection - Sufficient disk space (memory dumps can be 4-64 GB) - YARA rules for scanning memory for known malware signatures - Stri…

查看 SKILL 详情