Case A946ED · Blue team / DFIR · L3 Applied
Memory Forensics
Practise as: Explain it · Interview · Deep dive
Interview questionWhen and how would you do memory forensics on a compromised host?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Memory holds what disk does not: injected code, decrypted payloads, network connections, keys and command history.
- Acquire before reboot or isolation that kills processes: WinPmem, DumpIt, Magnet RAM Capture; hash the image.
- Volatility 3 plugins: windows.pslist/psscan for hidden processes, malfind for injected RWX regions, netscan.
- Look for parent-child anomalies (winword.exe spawning powershell.exe) and unsigned DLLs in trusted processes.
If the interviewer pushes back
- How does DKOM hide a process from pslist, and why can psscan still find it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.