> For the complete documentation index, see [llms.txt](https://neerajcysec.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://neerajcysec.gitbook.io/notes/memory-forensics/memory-forensics-13cubed/intro-to-memory-forensics.md).

# Intro to Memory Forensics

## Introduction

* Memory Analysis Tools - Volatility, Redline, Rekall
* Memory Acquisition Tools - FTKimager, Dumpit, Live RAM capture
* Memory doesn’t have a filesystem associated with it like ext4 or NTFS we’d see for disk-based forensics.
* Have to use plugins to parse the contents of a memory dump and extract the artifacts

<mark style="color:red;">`volatility -f {memory_image} imageinfo`</mark>

* Using <mark style="color:red;">`imageinfo`</mark> plugin allows the software to make a best guess as to the correct memory profile to use to parse the memory.
* Volatility searches for the KDGB (Kernel debugger) block - structure of memory used by Windows kernel for debugging purposes.
* Analysis of this structure will allow the software to determine the OS form which the memory dump originated.
* Getting this wrong will result in unexpected results or no results.

***

## Plugins

<mark style="color:red;">`volatility -f {memory_image} --profile=Win10x64_14393 {plugin}`</mark>

### Process list

<table><thead><tr><th width="129">PLUGIN</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><mark style="color:red;"><code>pslist</code></mark></td><td>allows us to see the running processes within the memory image</td></tr><tr><td><mark style="color:red;"><code>psscan</code></mark></td><td>shows in-depth and addtional processes that pslist did not find and even exited processes</td></tr><tr><td><mark style="color:red;"><code>pstree</code></mark></td><td>shows a hierarchical view of the processes that were running at the time of memory acquisition</td></tr></tbody></table>

* svchost.exe should always have the parent process as services.exe
* Redline tool has MRI (Malware Risk Index) which scores the process like if svchost.exe did not have the appropriate parent process, it would have a high score.

***

### Command line

<table><thead><tr><th width="177">PLUGIN</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><mark style="color:red;"><code>cmdscan</code></mark></td><td>prints the commands that the attacker typed</td></tr><tr><td><mark style="color:red;"><code>consoles</code></mark></td><td>shows the commands the attacker typed as well as the i/o buffer</td></tr></tbody></table>

***

### Dumping

<table><thead><tr><th width="370">PLUGIN</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><mark style="color:red;"><code>procdump -p {pid} --dump-dir=./</code></mark></td><td>dump the process (actual executable) mentioned in the given directory</td></tr><tr><td><mark style="color:red;"><code>memdump -p {pid} --dump-dir=./</code></mark></td><td>dump the memory associated with the process to disk</td></tr><tr><td><mark style="color:red;"><code>dumpfiles --dump-dir=./</code></mark></td><td>dump all files, including cached, available out of memory</td></tr></tbody></table>

* Once you dump a process, you get a Windows PE file. Use <mark style="color:red;">`file {file_name}`</mark> to confirm it.
* If you think that it is a malware, you can run strings, hash it and search in VirusTotal and find other IOCs.
* Programs that are frequently run are cached in memory.
* a process that’s running has no mapped file on disk associated with it (only exists in memory) can be a redflag that indicates a process injection occured

***

### Network connections

* can see data exfiltration using netscan.
* run *abbebus.py* against the file and it will find IP addresses within the netscan output ignoring private addresses.
* if you see a process listening and you think that is evil, you can take the “PID” and use <mark style="color:red;">`procdump`</mark> or <mark style="color:red;">`memdump`</mark> and dump the process to analyze it further.

***

### Registry information

<table><thead><tr><th width="171">PLUGIN</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><mark style="color:red;"><code>userassist</code></mark></td><td>show evidence of GUI based application execution</td></tr><tr><td><mark style="color:red;"><code>shellbags</code></mark></td><td>shows which windows explorer file paths have been viewed in the GUI</td></tr></tbody></table>

* <mark style="color:red;">`hivelist`</mark>, <mark style="color:red;">`hivescan`</mark>, <mark style="color:red;">`hivedump`</mark>, <mark style="color:red;">`shimcache`</mark>
* these plugins are not only available for disk-based forensics, but also for memory-based forensics.

***

### Others

<table><thead><tr><th width="171">PLUGIN</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><mark style="color:red;"><code>imagecopy</code></mark></td><td>performs a conversion of existing address space</td></tr></tbody></table>

* For example - a hibernation file, a crash dump file, a VMware snapshot file etc to a raw memory image
* So, if we use image copy, we can then take that output and then run volatility on it as if it was a memory dump file

<table><thead><tr><th width="171">PLUGIN</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><mark style="color:red;"><code>timeliner</code></mark></td><td>extracts timestamped artifacts out of memory</td></tr></tbody></table>

* You can then feed that into super timeline and create a comprehensive view of things that not only occured on disk but also on memory that have timedata associated with it.

***
