Views: 6
VOLATILITY 3
Memory Forensics Investigation Cheatsheet
DFIR | Detection Engineering | Threat Hunting | CyberDefenders Labs
01 โ SETUP & FUNDAMENTALS
# Install via pip
pip install volatility3
# Or clone from GitHub
git clone https://github.com/volatilityfoundation/volatility3.git
cd volatility3 && pip install -r requirements.txt
# Verify installation
python vol.py –version
Syntax Structure
# General syntax
python vol.py -f <memory.dump> <OS>.<plugin> [options]
# With output format
python vol.py -f <memory.dump> <OS>.<plugin> > output.txt
# Examples
python vol.py -f memdump.raw windows.pslist
python vol.py -f memdump.raw linux.bash
python vol.py -f memdump.raw mac.pslist
First Steps: Identify the OS / Profile
# Banner detection (recommended first step)
python vol.py -f memdump.raw banners.Banners
# Windows: check symbol layer
python vol.py -f memdump.raw windows.info
# Linux: identify kernel version
python vol.py -f memdump.raw linux.banner.Banner
๐ก NOTE: In Volatility 3, profiles are replaced by ISF (Intermediate Symbol Files). For Windows, symbols are auto-downloaded. For Linux, you must build or obtain the ISF for the specific kernel.
| Plugin | Description |
| windows.pslist | List all processes (EPROCESS doubly-linked list) |
| windows.pstree | Display processes in parent-child tree format |
| windows.psscan | Scan for EPROCESS structures (finds hidden/unlinked processes) |
| windows.cmdline | Extract command-line arguments for each process |
| windows.dlllist | List loaded DLLs for each process |
| windows.handles | Enumerate open handles (files, registry, threads, etc.) |
| windows.getsids | Show Security Identifier (SID) for each process |
| windows.privileges | List privileges assigned to each process |
| windows.envars | Display environment variables per process |
Process Filtering Examples
# Filter by specific PID
python vol.py -f memdump.raw windows.pslist –pid 1234
# Compare pslist vs psscan (detect hidden processes)
python vol.py -f memdump.raw windows.pslist | awk ‘{print $3}’ | sort > pslist_pids.txt
python vol.py -f memdump.raw windows.psscan | awk ‘{print $3}’ | sort > psscan_pids.txt
diff pslist_pids.txt psscan_pids.txt
# Get DLLs for a suspicious PID
python vol.py -f memdump.raw windows.dlllist –pid 1234
# Get cmdline for a specific process
python vol.py -f memdump.raw windows.cmdline –pid 1234
Process Investigation Checklist
- Parent-Child relationships โ svchost.exe should ONLY spawn from services.exe; explorer.exe from userinit.exe
- Process name spoofing โ Look for svchost.exe, lsass.exe, csrss.exe running from non-standard paths
- Orphaned processes โ Processes whose parent PID no longer exists
- Unusual process counts โ There should be only ONE lsass.exe, ONE services.exe, ONE winlogon.exe per session
- Timestamps โ Note creation time โ malware may inject into old processes or create processes with suspiciously early timestamps
03 โ NETWORK ANALYSIS
| Plugin | Description |
| windows.netstat | Active/recently-closed network connections (Vista+) |
| windows.netscan | Scan for connection structures (finds more artifacts) |
| windows.netstat –include-corrupt | Include potentially corrupt/incomplete entries |
Network Analysis Commands
# All network connections
python vol.py -f memdump.raw windows.netstat
# Scan-based approach (finds more artifacts)
python vol.py -f memdump.raw windows.netscan
# Save to file for grep analysis
python vol.py -f memdump.raw windows.netscan > net.txt
grep ESTABLISHED net.txt
grep -v ‘0.0.0.0’ net.txt | grep LISTEN
# Filter suspicious ports
grep -E ‘:(4444|1337|8080|443|80|22)’ net.txt
๐ก NOTE: netscan may find artifacts for already-closed connections that are still in memory. ESTABLISHED and CLOSE_WAIT states are highest priority during triage.
- Unusual remote IPs โ Cross-reference with threat intelligence; use whois/VirusTotal
- Non-browser processes connecting outbound โ e.g., cmd.exe, powershell.exe, rundll32.exe with ESTABLISHED connections
- Listening on unusual ports โ Backdoors commonly use ports >49152 or well-known ports
- Multiple connections to same C2 โ Consistent beaconing pattern
04 โ MEMORY & CODE INJECTION ANALYSIS
| Plugin | Description |
| windows.malfind | Find injected code based on VAD tags and PE headers |
| windows.vadinfo | Display Virtual Address Descriptor (VAD) entries |
| windows.vadwalk | Walk the VAD tree for a process |
| windows.vaddump | Dump memory regions from a process’s VAD |
| windows.memmap | Map memory regions for a process |
| windows.dumpfiles | Dump files cached in memory |
Malfind: Key Investigation Commands
# Scan all processes for injected code
python vol.py -f memdump.raw windows.malfind
# Scan specific PID
python vol.py -f memdump.raw windows.malfind –pid 1234
# Dump suspicious regions to disk for further analysis
python vol.py -f memdump.raw windows.malfind –dump
# Dump files (executable images) from memory
python vol.py -f memdump.raw windows.dumpfiles
python vol.py -f memdump.raw windows.dumpfiles –pid 1234
๐ก NOTE: Malfind flags regions with: RWX (Read/Write/Execute) permissions AND a PE header (MZ/4D5A). False positives exist โ always verify with additional analysis (strings, disassembly).
# List VAD entries for process
python vol.py -f memdump.raw windows.vadinfo –pid 1234
# Walk VAD tree
python vol.py -f memdump.raw windows.vadwalk –pid 1234
# Dump specific VAD region
python vol.py -f memdump.raw windows.vaddump –pid 1234 –dump
Injection Techniques Reference
| Technique | Detection Method |
| Classic DLL Injection | CreateRemoteThread + LoadLibrary โ look in windows.dlllist for anomalous DLL paths |
| Process Hollowing | Legit process replaced with malicious code โ pslist path vs PE header mismatch |
| Reflective DLL Injection | DLL loads itself from memory โ shows RWX regions with PE headers in malfind |
| Process Doppelganging | Uses NTFS transactions โ check for TxF artifacts |
| Atom Bombing | Uses atom tables โ difficult to detect, look for global atoms via handles |
| APC Injection | Asynchronous Procedure Calls โ look for unusual thread creations |
05 โ REGISTRY ANALYSIS
| Plugin | Description |
| windows.registry.hivelist | List all loaded registry hives in memory |
| windows.registry.hivescan | Scan for registry hive structures |
| windows.registry.printkey | Print subkeys and values for a given key path |
| windows.registry.userassist | Extract UserAssist entries (program execution evidence) |
| windows.registry.certificates | Dump certificates from the registry |
Registry Investigation Commands
# List all hives
python vol.py -f memdump.raw windows.registry.hivelist
# Print Run key (persistence)
python vol.py -f memdump.raw windows.registry.printkey
- -key ‘SOFTWAREMicrosoftWindowsCurrentVersionRun’
# Print RunOnce key
python vol.py -f memdump.raw windows.registry.printkey
- -key ‘SOFTWAREMicrosoftWindowsCurrentVersionRunOnce’
# UserAssist (GUI program execution history)
python vol.py -f memdump.raw windows.registry.userassist
# Services key (malware often installs as service)
python vol.py -f memdump.raw windows.registry.printkey
- -key ‘SYSTEMCurrentControlSetServices’
Critical Persistence Registry Locations
| Key Path | Significance |
| HKLMSoftwareMicrosoftWindowsCurrentVersionRun | Auto-run at system startup (all users) |
| HKCUSoftwareMicrosoftWindowsCurrentVersionRun | Auto-run for current user |
| HKLMSYSTEMCurrentControlSetServices | Installed services (malware as service) |
| HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon | Winlogon hooks |
| HKLMSYSTEMCurrentControlSetControlSession Manager | BootExecute โ very early execution |
| HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShell Folders | Shell startup folders |
06 โ FILESYSTEM & ARTIFACT EXTRACTION
| Plugin | Description |
| windows.filescan | Scan for FILE_OBJECT structures in memory |
| windows.dumpfiles | Dump file contents cached in memory |
| windows.mftscan.MFTScan | Scan for MFT (Master File Table) entries |
| windows.mftscan.ADS | Find Alternate Data Streams via MFT |
| windows.driverirp | List IRP handlers for loaded drivers |
| windows.driverscan | Scan for DRIVER_OBJECT structures |
| windows.modscan | Scan for kernel module/driver structures |
| windows.modules | List loaded kernel modules |
File Extraction Workflow
# Step 1: Find files of interest
python vol.py -f memdump.raw windows.filescan | grep -i ‘.exe’
python vol.py -f memdump.raw windows.filescan | grep -i ‘.dll’
python vol.py -f memdump.raw windows.filescan | grep -i ‘temp’
# Step 2: Extract using offset from filescan
python vol.py -f memdump.raw windows.dumpfiles –physaddr 0xABCDEF
# Step 3: Extract all files matching pattern
python vol.py -f memdump.raw windows.dumpfiles –filter ‘.*.exe’
# Check MFT for file history
python vol.py -f memdump.raw windows.mftscan.MFTScan
# Alternate Data Streams (hiding data)
python vol.py -f memdump.raw windows.mftscan.ADS
07 โ USER ACTIVITY & ARTIFACTS
| Plugin | Description |
| windows.registry.userassist | Programs executed via Explorer (ROT13-encoded) |
| windows.clipboard | Contents of the clipboard at dump time |
| windows.consolehistory | Commands typed in cmd.exe console sessions |
| windows.cmdline | Command-line arguments of all running processes |
| windows.hashdump | Extract NTLM password hashes from SAM/SYSTEM |
| windows.cachedump | Extract cached domain credentials |
| windows.lsadump | Extract LSA secrets |
Credential Extraction Commands
# Extract NTLM hashes (requires SYSTEM & SAM hive)
python vol.py -f memdump.raw windows.hashdump
# Cached domain credentials (DCC2 hashes)
python vol.py -f memdump.raw windows.cachedump
# LSA secrets (service account passwords, etc.)
python vol.py -f memdump.raw windows.lsadump
# Console history (attacker commands)
python vol.py -f memdump.raw windows.consolehistory
# Clipboard (may contain copied credentials)
python vol.py -f memdump.raw windows.clipboard
๐ก NOTE: Hashdump and lsadump require privilege. Extracted hashes can be cracked with hashcat or submitted to CrackStation. Console history is invaluable for reconstructing attacker activity.
| Plugin | Description |
| windows.modules | List loaded kernel modules (from linked list) |
| windows.modscan | Scan for MODULE_OBJECT structs (finds unlinked modules) |
| windows.driverscan | Scan for DRIVER_OBJECT structures |
| windows.driverirp | Show IRP dispatch table for drivers (hook detection) |
| windows.ssdt | Dump the System Service Descriptor Table (hook detection) |
| windows.idt | Display Interrupt Descriptor Table entries |
| windows.callbacks | List kernel notification callbacks |
| windows.svcscan | Scan for Windows service records |
| windows.getservicesids | Map service names to SIDs |
Rootkit Detection Workflow
# Compare loaded modules (modules) vs scan (modscan)
python vol.py -f memdump.raw windows.modules > modules.txt
python vol.py -f memdump.raw windows.modscan > modscan.txt
# Extract module names for diff
grep -oP ‘S+.sys’ modules.txt | sort > mod_list.txt
grep -oP ‘S+.sys’ modscan.txt | sort > modscan_list.txt
diff mod_list.txt modscan_list.txt
# Check SSDT for hooks
python vol.py -f memdump.raw windows.ssdt
# Check kernel callbacks (EDR evasion via callback removal)
python vol.py -f memdump.raw windows.callbacks
# Scan services (malicious services)
python vol.py -f memdump.raw windows.svcscan
09 โ STRING EXTRACTION & YARA SCANNING
| Plugin | Description |
| windows.strings | Map physical offsets to process context for found strings |
| windows.yarascan | Scan memory with YARA rules |
| linux.yarascan | YARA scan for Linux memory images |
String & YARA Commands
# Extract strings from raw dump first
strings -a -t d memdump.raw > all_strings.txt
strings -a -t d -e l memdump.raw >> all_strings.txt # Unicode
# Map strings to processes
python vol.py -f memdump.raw windows.strings –strings-file all_strings.txt
# YARA scan with inline rule
python vol.py -f memdump.raw windows.yarascan
- -yara-rules ‘rule malware { strings: $a = “malicious_string” condition: $a }’
# YARA scan with rule file
python vol.py -f memdump.raw windows.yarascan –yara-file myrules.yar
# Scan specific PID with YARA
python vol.py -f memdump.raw windows.yarascan
- -yara-rules ‘rule test { strings: $a = /http[s]?:/// condition: $a }’
- -pid 1234
Useful Strings to Search For
| String Pattern | Significance |
| http://, https:// | C2 URLs, download cradles |
| cmd.exe, powershell.exe | Command execution via dropped/injected code |
| \PIPE\, \.\ | Named pipe abuse (lateral movement) |
| VirtualAlloc, CreateRemoteThread | Injection API calls in strings |
| AAAA, /bin/sh, /bin/bash | Shellcode NOPs or Unix shells in Windows memory |
| base64 strings (long alphanum) | Encoded payloads โ decode and analyze |
| mimikatz, sekurlsa, lsadump | Credential dumping tool artifacts |
10 โ LINUX MEMORY ANALYSIS
| Plugin | Description |
| linux.pslist | List running processes from Linux task_struct |
| linux.pstree | Display parent-child process tree |
| linux.bash | Recover bash command history from memory |
| linux.elfs | List ELF binaries mapped in memory |
| linux.lsof | List open file descriptors per process |
| linux.netfilter | List Netfilter hooks (rootkit detection) |
| linux.check_afinfo | Detect hooks in network protocol structures |
| linux.check_syscall | Check syscall table for hooks |
| linux.kmsg | Read kernel log buffer from memory |
| linux.malfind | Find injected code in Linux processes |
| linux.mountinfo | List mounted filesystems |
| linux.envars | Environment variables from process memory |
Linux Investigation Commands
# Process list
python vol.py -f memdump.lime linux.pslist
# Bash history reconstruction
python vol.py -f memdump.lime linux.bash
# Check for syscall hooks (rootkits)
python vol.py -f memdump.lime linux.check_syscall
# Check network filter hooks
python vol.py -f memdump.lime linux.netfilter
# Open files/sockets per process
python vol.py -f memdump.lime linux.lsof
# Injected code detection
python vol.py -f memdump.lime linux.malfind
# Kernel messages (crash info, module loads)
python vol.py -f memdump.lime linux.kmsg
11 โ STRUCTURED INVESTIGATION WORKFLOW
# 1. Identify OS and build info
python vol.py -f memdump.raw banners.Banners
python vol.py -f memdump.raw windows.info
# 2. Get running processes (tree view)
python vol.py -f memdump.raw windows.pstree > processes.txt
# 3. Get network connections
python vol.py -f memdump.raw windows.netscan > network.txt
# 4. Get command lines
python vol.py -f memdump.raw windows.cmdline > cmdlines.txt
Phase 2: Process Investigation
# 5. Compare pslist vs psscan (find hidden processes)
python vol.py -f memdump.raw windows.pslist
python vol.py -f memdump.raw windows.psscan
# 6. Identify suspicious processes and get DLLs
python vol.py -f memdump.raw windows.dlllist –pid <SUSPICIOUS_PID>
# 7. Check handles for suspicious process
python vol.py -f memdump.raw windows.handles –pid <SUSPICIOUS_PID>
# 8. Run malfind on suspicious processes
python vol.py -f memdump.raw windows.malfind –pid <SUSPICIOUS_PID> –dump
Phase 3: Persistence & Lateral Movement
# 9. Check persistence registry keys
python vol.py -f memdump.raw windows.registry.printkey
- -key ‘SOFTWAREMicrosoftWindowsCurrentVersionRun’
# 10. Check services
python vol.py -f memdump.raw windows.svcscan > services.txt
# 11. Check scheduled tasks (look in filescan)
python vol.py -f memdump.raw windows.filescan | grep -i task
# 12. Console history (attacker typed commands)
python vol.py -f memdump.raw windows.consolehistory
Phase 4: Credential Harvesting Analysis
# 13. Check for credential dumping
python vol.py -f memdump.raw windows.hashdump
python vol.py -f memdump.raw windows.lsadump
# 14. Check clipboard for credentials
python vol.py -f memdump.raw windows.clipboard
# 15. Look for LSASS dump artifacts
python vol.py -f memdump.raw windows.filescan | grep -i lsass
Phase 5: Extraction & IOC Development
# 16. Dump malicious processes
python vol.py -f memdump.raw windows.dumpfiles –pid <SUSPICIOUS_PID>
# 17. Extract strings from dumped files
strings dumped_file.exe | grep -E ‘(http|cmd|powershell|\pipe)’
# 18. Hash dumped files for TI lookup
sha256sum dumped_file.exe
md5sum dumped_file.exe
# 19. Submit to VirusTotal API or MalwareBazaar
12 โ CYBERDEFENDERS QUICK-ANSWER REFERENCE
| Question | Plugin / Approach |
| What processes were running? | windows.pslist / windows.pstree |
| What network connections existed? | windows.netscan / windows.netstat |
| What was the parent of process X? | windows.pstree โ look at PPID column |
| What command was executed? | windows.cmdline / windows.consolehistory |
| What files were opened by a process? | windows.handles –pid X (filter for File) |
| What DLLs were loaded by a process? | windows.dlllist –pid X |
| Was there code injection? | windows.malfind –pid X |
| What registry keys were modified? | windows.registry.hivelist + printkey |
| Were credentials dumped? | windows.hashdump / windows.lsadump |
| What persistence was established? | windows.svcscan / registry Run keys |
| What is the OS version? | windows.info / banners.Banners |
| Are there hidden processes? | Diff pslist vs psscan outputs |
| Are there hidden drivers/modules? | Diff modules vs modscan outputs |
| What was in the clipboard? | windows.clipboard |
| Were there any suspicious drivers? | windows.driverscan / windows.driverirp |
Output Formatting Tips
# JSON output (for scripting)
python vol.py -f memdump.raw windows.pslist -r json
# Pretty print JSON
python vol.py -f memdump.raw windows.pslist -r json | python3 -m json.tool
# CSV output
python vol.py -f memdump.raw windows.pslist -r csv
# Quick timestamp check on a process
python vol.py -f memdump.raw windows.pslist | grep -i <processname>
# Verbose output
python vol.py -f memdump.raw windows.pslist -v
# Redirect + grep workflow
python vol.py -f memdump.raw windows.netscan | grep -v ‘CLOSED’ | grep -v ‘0.0.0.0’
Reference: Volatility 3 Docs โ https://volatility3.readthedocs.io | MITRE ATT&CK Memory Techniques โ TA0005, T1055, T1003, T1547

