Volatility3: Memory Forensics Cheatsheet

Volatility3: Memory Forensics Cheatsheet

Views: 6

VOLATILITY 3

Memory Forensics Investigation Cheatsheet

DFIR | Detection Engineering | Threat Hunting | CyberDefenders Labs

01 โ”‚ SETUP & FUNDAMENTALS

# Install via pip

pip install volatility3

# Or clone from GitHub

git clone https://github.com/volatilityfoundation/volatility3.git

cd volatility3 && pip install -r requirements.txt

# Verify installation

python vol.py –version


Syntax Structure

# General syntax

python vol.py -f <memory.dump> <OS>.<plugin> [options]

# With output format

python vol.py -f <memory.dump> <OS>.<plugin> > output.txt

# Examples

python vol.py -f memdump.raw windows.pslist

python vol.py -f memdump.raw linux.bash

python vol.py -f memdump.raw mac.pslist


First Steps: Identify the OS / Profile

# Banner detection (recommended first step)

python vol.py -f memdump.raw banners.Banners

# Windows: check symbol layer

python vol.py -f memdump.raw windows.info

# Linux: identify kernel version

python vol.py -f memdump.raw linux.banner.Banner


๐Ÿ’ก NOTE: In Volatility 3, profiles are replaced by ISF (Intermediate Symbol Files). For Windows, symbols are auto-downloaded. For Linux, you must build or obtain the ISF for the specific kernel.

PluginDescription
windows.pslistList all processes (EPROCESS doubly-linked list)
windows.pstreeDisplay processes in parent-child tree format
windows.psscanScan for EPROCESS structures (finds hidden/unlinked processes)
windows.cmdlineExtract command-line arguments for each process
windows.dlllistList loaded DLLs for each process
windows.handlesEnumerate open handles (files, registry, threads, etc.)
windows.getsidsShow Security Identifier (SID) for each process
windows.privilegesList privileges assigned to each process
windows.envarsDisplay environment variables per process

Process Filtering Examples

# Filter by specific PID

python vol.py -f memdump.raw windows.pslist –pid 1234

# Compare pslist vs psscan (detect hidden processes)

python vol.py -f memdump.raw windows.pslist | awk ‘{print $3}’ | sort > pslist_pids.txt

python vol.py -f memdump.raw windows.psscan | awk ‘{print $3}’ | sort > psscan_pids.txt

diff pslist_pids.txt psscan_pids.txt

# Get DLLs for a suspicious PID

python vol.py -f memdump.raw windows.dlllist –pid 1234

# Get cmdline for a specific process

python vol.py -f memdump.raw windows.cmdline –pid 1234


Process Investigation Checklist

  • Parent-Child relationships โ€” svchost.exe should ONLY spawn from services.exe; explorer.exe from userinit.exe
  • Process name spoofing โ€” Look for svchost.exe, lsass.exe, csrss.exe running from non-standard paths
  • Orphaned processes โ€” Processes whose parent PID no longer exists
  • Unusual process counts โ€” There should be only ONE lsass.exe, ONE services.exe, ONE winlogon.exe per session
  • Timestamps โ€” Note creation time โ€” malware may inject into old processes or create processes with suspiciously early timestamps

03 โ”‚ NETWORK ANALYSIS

PluginDescription
windows.netstatActive/recently-closed network connections (Vista+)
windows.netscanScan for connection structures (finds more artifacts)
windows.netstat –include-corruptInclude potentially corrupt/incomplete entries

Network Analysis Commands

# All network connections

python vol.py -f memdump.raw windows.netstat

# Scan-based approach (finds more artifacts)

python vol.py -f memdump.raw windows.netscan

# Save to file for grep analysis

python vol.py -f memdump.raw windows.netscan > net.txt

grep ESTABLISHED net.txt

grep -v ‘0.0.0.0’ net.txt | grep LISTEN

# Filter suspicious ports

grep -E ‘:(4444|1337|8080|443|80|22)’ net.txt


๐Ÿ’ก NOTE: netscan may find artifacts for already-closed connections that are still in memory. ESTABLISHED and CLOSE_WAIT states are highest priority during triage.

  • Unusual remote IPs โ€” Cross-reference with threat intelligence; use whois/VirusTotal
  • Non-browser processes connecting outbound โ€” e.g., cmd.exe, powershell.exe, rundll32.exe with ESTABLISHED connections
  • Listening on unusual ports โ€” Backdoors commonly use ports >49152 or well-known ports
  • Multiple connections to same C2 โ€” Consistent beaconing pattern

04 โ”‚ MEMORY & CODE INJECTION ANALYSIS

PluginDescription
windows.malfindFind injected code based on VAD tags and PE headers
windows.vadinfoDisplay Virtual Address Descriptor (VAD) entries
windows.vadwalkWalk the VAD tree for a process
windows.vaddumpDump memory regions from a process’s VAD
windows.memmapMap memory regions for a process
windows.dumpfilesDump files cached in memory

Malfind: Key Investigation Commands

# Scan all processes for injected code

python vol.py -f memdump.raw windows.malfind

# Scan specific PID

python vol.py -f memdump.raw windows.malfind –pid 1234

# Dump suspicious regions to disk for further analysis

python vol.py -f memdump.raw windows.malfind –dump

# Dump files (executable images) from memory

python vol.py -f memdump.raw windows.dumpfiles

python vol.py -f memdump.raw windows.dumpfiles –pid 1234


๐Ÿ’ก NOTE: Malfind flags regions with: RWX (Read/Write/Execute) permissions AND a PE header (MZ/4D5A). False positives exist โ€” always verify with additional analysis (strings, disassembly).

# List VAD entries for process

python vol.py -f memdump.raw windows.vadinfo –pid 1234

# Walk VAD tree

python vol.py -f memdump.raw windows.vadwalk –pid 1234

# Dump specific VAD region

python vol.py -f memdump.raw windows.vaddump –pid 1234 –dump


Injection Techniques Reference

TechniqueDetection Method
Classic DLL InjectionCreateRemoteThread + LoadLibrary โ€” look in windows.dlllist for anomalous DLL paths
Process HollowingLegit process replaced with malicious code โ€” pslist path vs PE header mismatch
Reflective DLL InjectionDLL loads itself from memory โ€” shows RWX regions with PE headers in malfind
Process DoppelgangingUses NTFS transactions โ€” check for TxF artifacts
Atom BombingUses atom tables โ€” difficult to detect, look for global atoms via handles
APC InjectionAsynchronous Procedure Calls โ€” look for unusual thread creations

05 โ”‚ REGISTRY ANALYSIS

PluginDescription
windows.registry.hivelistList all loaded registry hives in memory
windows.registry.hivescanScan for registry hive structures
windows.registry.printkeyPrint subkeys and values for a given key path
windows.registry.userassistExtract UserAssist entries (program execution evidence)
windows.registry.certificatesDump certificates from the registry

Registry Investigation Commands

# List all hives

python vol.py -f memdump.raw windows.registry.hivelist

# Print Run key (persistence)

python vol.py -f memdump.raw windows.registry.printkey

  • -key ‘SOFTWAREMicrosoftWindowsCurrentVersionRun’

# Print RunOnce key

python vol.py -f memdump.raw windows.registry.printkey

  • -key ‘SOFTWAREMicrosoftWindowsCurrentVersionRunOnce’

# UserAssist (GUI program execution history)

python vol.py -f memdump.raw windows.registry.userassist

# Services key (malware often installs as service)

python vol.py -f memdump.raw windows.registry.printkey

  • -key ‘SYSTEMCurrentControlSetServices’

Critical Persistence Registry Locations

Key PathSignificance
HKLMSoftwareMicrosoftWindowsCurrentVersionRunAuto-run at system startup (all users)
HKCUSoftwareMicrosoftWindowsCurrentVersionRunAuto-run for current user
HKLMSYSTEMCurrentControlSetServicesInstalled services (malware as service)
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonWinlogon hooks
HKLMSYSTEMCurrentControlSetControlSession ManagerBootExecute โ€” very early execution
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShell FoldersShell startup folders

06 โ”‚ FILESYSTEM & ARTIFACT EXTRACTION

PluginDescription
windows.filescanScan for FILE_OBJECT structures in memory
windows.dumpfilesDump file contents cached in memory
windows.mftscan.MFTScanScan for MFT (Master File Table) entries
windows.mftscan.ADSFind Alternate Data Streams via MFT
windows.driverirpList IRP handlers for loaded drivers
windows.driverscanScan for DRIVER_OBJECT structures
windows.modscanScan for kernel module/driver structures
windows.modulesList loaded kernel modules

File Extraction Workflow

# Step 1: Find files of interest

python vol.py -f memdump.raw windows.filescan | grep -i ‘.exe’

python vol.py -f memdump.raw windows.filescan | grep -i ‘.dll’

python vol.py -f memdump.raw windows.filescan | grep -i ‘temp’

# Step 2: Extract using offset from filescan

python vol.py -f memdump.raw windows.dumpfiles –physaddr 0xABCDEF

# Step 3: Extract all files matching pattern

python vol.py -f memdump.raw windows.dumpfiles –filter ‘.*.exe’

# Check MFT for file history

python vol.py -f memdump.raw windows.mftscan.MFTScan

# Alternate Data Streams (hiding data)

python vol.py -f memdump.raw windows.mftscan.ADS


07 โ”‚ USER ACTIVITY & ARTIFACTS

PluginDescription
windows.registry.userassistPrograms executed via Explorer (ROT13-encoded)
windows.clipboardContents of the clipboard at dump time
windows.consolehistoryCommands typed in cmd.exe console sessions
windows.cmdlineCommand-line arguments of all running processes
windows.hashdumpExtract NTLM password hashes from SAM/SYSTEM
windows.cachedumpExtract cached domain credentials
windows.lsadumpExtract LSA secrets

Credential Extraction Commands

# Extract NTLM hashes (requires SYSTEM & SAM hive)

python vol.py -f memdump.raw windows.hashdump

# Cached domain credentials (DCC2 hashes)

python vol.py -f memdump.raw windows.cachedump

# LSA secrets (service account passwords, etc.)

python vol.py -f memdump.raw windows.lsadump

# Console history (attacker commands)

python vol.py -f memdump.raw windows.consolehistory

# Clipboard (may contain copied credentials)

python vol.py -f memdump.raw windows.clipboard


๐Ÿ’ก NOTE: Hashdump and lsadump require privilege. Extracted hashes can be cracked with hashcat or submitted to CrackStation. Console history is invaluable for reconstructing attacker activity.

PluginDescription
windows.modulesList loaded kernel modules (from linked list)
windows.modscanScan for MODULE_OBJECT structs (finds unlinked modules)
windows.driverscanScan for DRIVER_OBJECT structures
windows.driverirpShow IRP dispatch table for drivers (hook detection)
windows.ssdtDump the System Service Descriptor Table (hook detection)
windows.idtDisplay Interrupt Descriptor Table entries
windows.callbacksList kernel notification callbacks
windows.svcscanScan for Windows service records
windows.getservicesidsMap service names to SIDs

Rootkit Detection Workflow

# Compare loaded modules (modules) vs scan (modscan)

python vol.py -f memdump.raw windows.modules > modules.txt

python vol.py -f memdump.raw windows.modscan > modscan.txt

# Extract module names for diff

grep -oP ‘S+.sys’ modules.txt | sort > mod_list.txt

grep -oP ‘S+.sys’ modscan.txt | sort > modscan_list.txt

diff mod_list.txt modscan_list.txt

# Check SSDT for hooks

python vol.py -f memdump.raw windows.ssdt

# Check kernel callbacks (EDR evasion via callback removal)

python vol.py -f memdump.raw windows.callbacks

# Scan services (malicious services)

python vol.py -f memdump.raw windows.svcscan


09 โ”‚ STRING EXTRACTION & YARA SCANNING

PluginDescription
windows.stringsMap physical offsets to process context for found strings
windows.yarascanScan memory with YARA rules
linux.yarascanYARA scan for Linux memory images

String & YARA Commands

# Extract strings from raw dump first

strings -a -t d memdump.raw > all_strings.txt

strings -a -t d -e l memdump.raw >> all_strings.txt # Unicode

# Map strings to processes

python vol.py -f memdump.raw windows.strings –strings-file all_strings.txt

# YARA scan with inline rule

python vol.py -f memdump.raw windows.yarascan

  • -yara-rules ‘rule malware { strings: $a = “malicious_string” condition: $a }’

# YARA scan with rule file

python vol.py -f memdump.raw windows.yarascan –yara-file myrules.yar

# Scan specific PID with YARA

python vol.py -f memdump.raw windows.yarascan

  • -yara-rules ‘rule test { strings: $a = /http[s]?:/// condition: $a }’
  • -pid 1234

Useful Strings to Search For

String PatternSignificance
http://, https://C2 URLs, download cradles
cmd.exe, powershell.exeCommand execution via dropped/injected code
\PIPE\, \.\Named pipe abuse (lateral movement)
VirtualAlloc, CreateRemoteThreadInjection API calls in strings
AAAA, /bin/sh, /bin/bashShellcode NOPs or Unix shells in Windows memory
base64 strings (long alphanum)Encoded payloads โ€” decode and analyze
mimikatz, sekurlsa, lsadumpCredential dumping tool artifacts

10 โ”‚ LINUX MEMORY ANALYSIS

PluginDescription
linux.pslistList running processes from Linux task_struct
linux.pstreeDisplay parent-child process tree
linux.bashRecover bash command history from memory
linux.elfsList ELF binaries mapped in memory
linux.lsofList open file descriptors per process
linux.netfilterList Netfilter hooks (rootkit detection)
linux.check_afinfoDetect hooks in network protocol structures
linux.check_syscallCheck syscall table for hooks
linux.kmsgRead kernel log buffer from memory
linux.malfindFind injected code in Linux processes
linux.mountinfoList mounted filesystems
linux.envarsEnvironment variables from process memory

Linux Investigation Commands

# Process list

python vol.py -f memdump.lime linux.pslist

# Bash history reconstruction

python vol.py -f memdump.lime linux.bash

# Check for syscall hooks (rootkits)

python vol.py -f memdump.lime linux.check_syscall

# Check network filter hooks

python vol.py -f memdump.lime linux.netfilter

# Open files/sockets per process

python vol.py -f memdump.lime linux.lsof

# Injected code detection

python vol.py -f memdump.lime linux.malfind

# Kernel messages (crash info, module loads)

python vol.py -f memdump.lime linux.kmsg


11 โ”‚ STRUCTURED INVESTIGATION WORKFLOW

# 1. Identify OS and build info

python vol.py -f memdump.raw banners.Banners

python vol.py -f memdump.raw windows.info

# 2. Get running processes (tree view)

python vol.py -f memdump.raw windows.pstree > processes.txt

# 3. Get network connections

python vol.py -f memdump.raw windows.netscan > network.txt

# 4. Get command lines

python vol.py -f memdump.raw windows.cmdline > cmdlines.txt


Phase 2: Process Investigation

# 5. Compare pslist vs psscan (find hidden processes)

python vol.py -f memdump.raw windows.pslist

python vol.py -f memdump.raw windows.psscan

# 6. Identify suspicious processes and get DLLs

python vol.py -f memdump.raw windows.dlllist –pid <SUSPICIOUS_PID>

# 7. Check handles for suspicious process

python vol.py -f memdump.raw windows.handles –pid <SUSPICIOUS_PID>

# 8. Run malfind on suspicious processes

python vol.py -f memdump.raw windows.malfind –pid <SUSPICIOUS_PID> –dump


Phase 3: Persistence & Lateral Movement

# 9. Check persistence registry keys

python vol.py -f memdump.raw windows.registry.printkey

  • -key ‘SOFTWAREMicrosoftWindowsCurrentVersionRun’

# 10. Check services

python vol.py -f memdump.raw windows.svcscan > services.txt

# 11. Check scheduled tasks (look in filescan)

python vol.py -f memdump.raw windows.filescan | grep -i task

# 12. Console history (attacker typed commands)

python vol.py -f memdump.raw windows.consolehistory


Phase 4: Credential Harvesting Analysis

# 13. Check for credential dumping

python vol.py -f memdump.raw windows.hashdump

python vol.py -f memdump.raw windows.lsadump

# 14. Check clipboard for credentials

python vol.py -f memdump.raw windows.clipboard

# 15. Look for LSASS dump artifacts

python vol.py -f memdump.raw windows.filescan | grep -i lsass


Phase 5: Extraction & IOC Development

# 16. Dump malicious processes

python vol.py -f memdump.raw windows.dumpfiles –pid <SUSPICIOUS_PID>

# 17. Extract strings from dumped files

strings dumped_file.exe | grep -E ‘(http|cmd|powershell|\pipe)’

# 18. Hash dumped files for TI lookup

sha256sum dumped_file.exe

md5sum dumped_file.exe

# 19. Submit to VirusTotal API or MalwareBazaar


12 โ”‚ CYBERDEFENDERS QUICK-ANSWER REFERENCE

QuestionPlugin / Approach
What processes were running?windows.pslist / windows.pstree
What network connections existed?windows.netscan / windows.netstat
What was the parent of process X?windows.pstree โ†’ look at PPID column
What command was executed?windows.cmdline / windows.consolehistory
What files were opened by a process?windows.handles –pid X (filter for File)
What DLLs were loaded by a process?windows.dlllist –pid X
Was there code injection?windows.malfind –pid X
What registry keys were modified?windows.registry.hivelist + printkey
Were credentials dumped?windows.hashdump / windows.lsadump
What persistence was established?windows.svcscan / registry Run keys
What is the OS version?windows.info / banners.Banners
Are there hidden processes?Diff pslist vs psscan outputs
Are there hidden drivers/modules?Diff modules vs modscan outputs
What was in the clipboard?windows.clipboard
Were there any suspicious drivers?windows.driverscan / windows.driverirp

Output Formatting Tips

# JSON output (for scripting)

python vol.py -f memdump.raw windows.pslist -r json

# Pretty print JSON

python vol.py -f memdump.raw windows.pslist -r json | python3 -m json.tool

# CSV output

python vol.py -f memdump.raw windows.pslist -r csv

# Quick timestamp check on a process

python vol.py -f memdump.raw windows.pslist | grep -i <processname>

# Verbose output

python vol.py -f memdump.raw windows.pslist -v

# Redirect + grep workflow

python vol.py -f memdump.raw windows.netscan | grep -v ‘CLOSED’ | grep -v ‘0.0.0.0’


Reference: Volatility 3 Docs โ€” https://volatility3.readthedocs.io | MITRE ATT&CK Memory Techniques โ€” TA0005, T1055, T1003, T1547