Skip to main content

Volatility

Advanced Memory Forensics: Analysis Techniques

··6630 words·32 mins· loading · loading
This article explores advanced memory forensics techniques for detecting malicious activity in memory, including process timelining, high-low level analysis, walking the VAD tree, and detecting rogue processes, kernel-level rootkits, DLL hijacking, process hollowing, and sophisticated persistence mechanisms.

Anti-Forensics: Knowing What They See (Memory Analysis)

··587 words·3 mins· loading · loading
To hide in memory, you must study memory. This guide flips the script on forensics, using Volatility to understand how Blue Teams hunt for your beacons.