All skills
wshobson avatar

/memory-forensics

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.

Use this Skill: https://skilld.dev/gh/wshobson/agents/memory-forensics

This session only. Nothing lands on disk.

referencesdetails.md

≈681 tokens on demand. Your agent reads this file only when SKILL.md points to it.

memory-forensics — detailed sections

Volatility 3 Framework

Installation and Setup

# Install Volatility 3
pip install volatility3

# Install symbol tables (Windows)
# Download from https://downloads.volatilityfoundation.org/volatility3/symbols/

# Basic usage
vol -f memory.raw <plugin>

# With symbol path
vol -f memory.raw -s /path/to/symbols windows.pslist

Essential Plugins

Process Analysis
# List processes
vol -f memory.raw windows.pslist

# Process tree (parent-child relationships)
vol -f memory.raw windows.pstree

# Hidden process detection
vol -f memory.raw windows.psscan

# Process memory dumps
vol -f memory.raw windows.memmap --pid <PID> --dump

# Process environment variables
vol -f memory.raw windows.envars --pid <PID>

# Command line arguments
vol -f memory.raw windows.cmdline
Network Analysis
# Network connections
vol -f memory.raw windows.netscan

# Network connection state
vol -f memory.raw windows.netstat
DLL and Module Analysis
# Loaded DLLs per process
vol -f memory.raw windows.dlllist --pid <PID>

# Find hidden/injected DLLs
vol -f memory.raw windows.ldrmodules

# Kernel modules
vol -f memory.raw windows.modules

# Module dumps
vol -f memory.raw windows.moddump --pid <PID>
Memory Injection Detection
# Detect code injection
vol -f memory.raw windows.malfind

# VAD (Virtual Address Descriptor) analysis
vol -f memory.raw windows.vadinfo --pid <PID>

# Dump suspicious memory regions
vol -f memory.raw windows.vadyarascan --yara-rules rules.yar
Registry Analysis
# List registry hives
vol -f memory.raw windows.registry.hivelist

# Print registry key
vol -f memory.raw windows.registry.printkey --key "Software\Microsoft\Windows\CurrentVersion\Run"

# Dump registry hive
vol -f memory.raw windows.registry.hivescan --dump
File System Artifacts
# Scan for file objects
vol -f memory.raw windows.filescan

# Dump files from memory
vol -f memory.raw windows.dumpfiles --pid <PID>

# MFT analysis
vol -f memory.raw windows.mftscan

Linux Analysis

# Process listing
vol -f memory.raw linux.pslist

# Process tree
vol -f memory.raw linux.pstree

# Bash history
vol -f memory.raw linux.bash

# Network connections
vol -f memory.raw linux.sockstat

# Loaded kernel modules
vol -f memory.raw linux.lsmod

# Mount points
vol -f memory.raw linux.mount

# Environment variables
vol -f memory.raw linux.envars

macOS Analysis

# Process listing
vol -f memory.raw mac.pslist

# Process tree
vol -f memory.raw mac.pstree

# Network connections
vol -f memory.raw mac.netstat

# Kernel extensions
vol -f memory.raw mac.lsmod

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The memory-forensics skill is a technical guide for incident response and malware analysis. It involves high-privilege system operations and the processing of untrusted forensic artifacts, which are standard practices for its intended use case.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
  • volatility
  • memory-forensics
  • incident-response
  • malware-analysis
  • windows
  • linux
  • macos
  • yara
  • artifact-extraction
  • acquisition

README badge

README badge for wshobson/agents/memory-forensics

Acquires and analyzes memory dumps using Volatility 3 to extract malware artifacts, process injection indicators, rootkits, and credentials from Windows, Linux, and macOS systems. Covers live acquisition tools (WinPmem, LiME, osxpmem), malware analysis workflows with malfind and YARA scanning, and incident response techniques including timeline reconstruction and persistence mechanism detection.

Generated from the current SKILL.md.

Does this skill cover memory acquisition for all operating systems?
Yes. The skill includes acquisition tools and techniques for Windows (WinPmem, DumpIt), Linux (LiME, /dev/mem), and macOS (osxpmem), plus virtual machine memory capture from VMware, VirtualBox, QEMU, and Hyper-V.
What memory analysis framework does this skill use?
The skill primarily uses Volatility 3 framework for analyzing memory dumps, with additional coverage of Rekall. It includes specific Volatility commands for process analysis, network connections, malware detection, and credential extraction.
Can this skill help detect malware and rootkits in memory?
Yes. The skill covers process injection detection via malfind, rootkit detection through process list comparison and SSDT hooks, YARA rule integration for scanning, and credential extraction techniques.
Does this skill include YARA integration?
Yes. The skill explains how to write YARA rules for memory analysis, provides example rules for injection shellcode and Cobalt Strike beacons, and shows how to scan memory and kernel space using Volatility's yarascan plugin.
What incident response workflows does this skill cover?
The skill includes workflows for user activity analysis, timeline reconstruction, persistence mechanism detection, service enumeration, scheduled task discovery, and recent file recovery from memory.

Generated from the current SKILL.md. These answers refresh after source changes.