Open cardosec

Case A946ED · Blue team / DFIR · L3 Applied

Memory Forensics

Practise as: Explain it · Interview · Deep dive

Interview questionWhen and how would you do memory forensics on a compromised host?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Memory holds what disk does not: injected code, decrypted payloads, network connections, keys and command history.
  2. Acquire before reboot or isolation that kills processes: WinPmem, DumpIt, Magnet RAM Capture; hash the image.
  3. Volatility 3 plugins: windows.pslist/psscan for hidden processes, malfind for injected RWX regions, netscan.
  4. Look for parent-child anomalies (winword.exe spawning powershell.exe) and unsigned DLLs in trusted processes.

If the interviewer pushes back

  • How does DKOM hide a process from pslist, and why can psscan still find it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.