#memoryforensics — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #memoryforensics, aggregated by home.social.
-
RE: https://infosec.exchange/@volexity/116958370224493580
Heading to Las Vegas next week? Connect with our team to discuss the latest in #DFIR, #memoryforensics, active threat actor campaigns we're tracking, and more!
Let us know when you'd like to meet: https://www.volexity.com/contact/meet-up-in-vegas/ -
@volexity is hiring!
Join a team that develops concrete solutions to the most challenging real-world problems. Whether your focus is bringing new products to market or delivering cybersecurity services to customers worldwide, the work you do here helps real people and moves the industry forward.
See how you can plug in: https://www.volexity.com/company/careers/
#dfir #hiring #memoryforensics #threatintel #cybersecurity -
Analyze Linux process arguments and environment directly from kernel memory using Volatility 3's linux.psaux.PsAux plugin. It walks task_struct to access mm_struct and reads user-space stack strings—more reliable than /proc/[pid]/cmdline during live analysis. #volatility #linuxforensics #memoryforensics
https://www.valtersit.com/vault/analyze-linux-process-arguments-and-environment-from-kernel--cdbc4a/
-
@volexity is heading to Las Vegas! Members of our leadership, development, engineering & threat intelligence teams will be on site August 4–6.
If you would like to connect to discuss the latest in #DFIR, #memoryforensics, or the current threat landscape, let us know when you’d like to meet: https://www.volexity.com/contact/meet-up-in-vegas/
-
@volexity has published details on a recent incident response investigation involving the exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. Volexity attributes this activity to a threat actor it tracks as UTA0533, with the earliest signs of compromise dating back to June 22, 2026.
SonicWall has released patches (versions 12.4.3-03453 and 12.5.0-02835) following their July 14 public disclosure. Organizations using affected SMA 1000 series devices should upgrade immediately.
Read our full technical breakdown, including the vulnerability workflow, malware analysis, and IOCs: https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/
-
Great conversations at #FIRSTCON26 so far! Come say hello to the @volexity team at Booth 7 & see how to rapidly resolve your investigations and find what other tools are missing.
-
We are excited to welcome our 2026 #summerinternship students from Department of Computer Science programs at University of Notre Dame & University of Maryland and Maryland Applied Graduate Engineering! Over the next few months, they will be working alongside our engineering and threat intelligence teams on core software development and #memoryforensics research.
Learn more about our program and future opportunities: https://www.volexity.com/internships/
#dfir -
RE: https://infosec.exchange/@jackrhysider/116523222332876813
The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @jackrhysider for mentioning our work!
@volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild.
Read our blog post for the original research mentioned: https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
-
@volexity Volcano Server & Volcano One v26.04.27 adds memory analysis for arm64 Windows, memory-only .NET assemblies, SRUM database, Linux systemd units, history & timers from RAM.
This release also adds detection of AppleScript usage, cleared Windows event logs, AV scanning of files & deployments across AWS accounts.
Contact us for more information: https://volexity.com/company/contact/
-
🎖️ El Curso Fundamentos de Forense Digital está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_Fundamentos_de_Forense_Digital #memoryforensics #networkforensics #forensictools #digitalevidence #cybercrime #dfir #digitalforensics -
🎖️ El Curso de Informática Forense está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_de_Informatica_Forense #digitalforensics #dfir #computerforensics #memoryforensics #diskforensics #datarecovery #cybercrime -
Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.
It also uses SQL-based queries to perform analysis, similar to #OSquery.
https://blog.trailofbits.com/2026/02/25/mquire-linux-memory-forensics-without-external-dependencies/
-
Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.
It also uses SQL-based queries to perform analysis, similar to #OSquery.
https://blog.trailofbits.com/2026/02/25/mquire-linux-memory-forensics-without-external-dependencies/
-
🚀 Ah yes, the modern-day alchemist's dream: extract memories faster than your grandma can forget them! 🧠🔍 GitHub's latest concoction promises to make memory forensics as breezy as a summer’s fart—assuming you can navigate the UI from 1995. ⚙️💻
https://github.com/volatilityfoundation/volatility3 #memoryforensics #GitHub #techinnovation #UXdesign #digitalalchemy #HackerNews #ngated -
🚀 Ah yes, the modern-day alchemist's dream: extract memories faster than your grandma can forget them! 🧠🔍 GitHub's latest concoction promises to make memory forensics as breezy as a summer’s fart—assuming you can navigate the UI from 1995. ⚙️💻
https://github.com/volatilityfoundation/volatility3 #memoryforensics #GitHub #techinnovation #UXdesign #digitalalchemy #HackerNews #ngated -
Update:
Our velociraptor plugin `Windows.Memory.Mem2Disk` can detect RAM injections and fileless malware.
We tested it against (among others) the C2 frameworks Sliver, Havoc and Mythic. All three were detected.
It was recently featured in a blog post by Mike Cohen:
https://docs.velociraptor.app/blog/2025/2025-11-15-memory-analysis-pt1
Stay tuned for memory analysis with velo part 2!
#C2 #detection #memoryforensics #velociraptor #DFIR #cybersecurity #infosec #pwr2
-
Awesome blogpost on how to dump
shmon Linux:https://isc.sans.edu/diary/How+to+collect+memoryonly+filesystems+on+Linux+systems/32432/
-
Awesome blogpost on how to dump
shmon Linux:https://isc.sans.edu/diary/How+to+collect+memoryonly+filesystems+on+Linux+systems/32432/
-
Today we have another #DEFCONTraining Bahrain Spotlight - “A Complete Practical Approach to Malware Analysis & Threat Hunting with Memory Forensics, Endpoint Telemetry, & AI-Driven Hunting” with Monnappa K A and Sajan Shetty on November 3-4.
This 2-day intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. The course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.
What makes this training unique and future-ready is the introduction to the concept of AI-powered autonomous hunting with the Garuda Threat Hunting Framework.
Take a deeper look and register for this course today: https://training.defcon.org/collections/arab-cybersecurity-2025/products/monnappa-k-a-a-complete-practical-approach-to-malware-analysis-threat-hunting-using-memory-forensics-dctlv2025-copy
Explore the full list of offerings in Bahrain at https://training.defcon.org/collections/arab-cybersecurity-2025
#defcon #cyber #training #defconbahrain #AICS2025 #Bahrain #UAE #SaudiArabia #cybertraining #infosec #cybersecurity #cyberdefense #malwareanalysis #threathunting #memoryforensics #AI #endpointtelemetry -
Today we have another #DEFCONTraining Bahrain Spotlight - “A Complete Practical Approach to Malware Analysis & Threat Hunting with Memory Forensics, Endpoint Telemetry, & AI-Driven Hunting” with Monnappa K A and Sajan Shetty on November 3-4.
This 2-day intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. The course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.
What makes this training unique and future-ready is the introduction to the concept of AI-powered autonomous hunting with the Garuda Threat Hunting Framework.
Take a deeper look and register for this course today: https://training.defcon.org/collections/arab-cybersecurity-2025/products/monnappa-k-a-a-complete-practical-approach-to-malware-analysis-threat-hunting-using-memory-forensics-dctlv2025-copy
Explore the full list of offerings in Bahrain at https://training.defcon.org/collections/arab-cybersecurity-2025
#defcon #cyber #training #defconbahrain #AICS2025 #Bahrain #UAE #SaudiArabia #cybertraining #infosec #cybersecurity #cyberdefense #malwareanalysis #threathunting #memoryforensics #AI #endpointtelemetry -
@volexity researchers will be presenting at THREE conferences in Las Vegas this August! Here’s where you can hear about some of our latest research in #memoryforensics and automated malicious script detection and de-obfuscation:
Monday, August 4: Detecting, Deobfuscating, and Preventing Obfuscated Script Execution with Tree-sitter @ BSides Las Vegas (https://bsideslv.org/talks#LBQDEB)
Wednesday, August 6: Volatility 3 @ Black Hat Arsenal (https://www.blackhat.com/us-25/arsenal/schedule/#volatility-3-44745)
Friday, August 8: Effectively Detecting Modern Malware with Volatility 3 Workshop @ DEF CON 33 (https://defcon.org/html/defcon-33/dc-33-workshops.html#content_60679)
Many members of the @volexity team will be also in Vegas, so if you’d like to meet up with our leadership, development, engineering, services, or threat intelligence teams, please reach out or complete our contact form: https://www.volexity.com/contact/meet-up-in-vegas/ -
Doing some interesting #memoryforensics on @signalapp tonight. Still would trust them with my life, and the lives of my friends, but interesting stuff in the memory.
For instance, people I haven't talked to in 3 years showed up in the memory dump with a field called "SharedGroupNames" that listed every group that both I and that individual were associated with.
Also, the "LastMessage" field was often populated with a plaintext version of the last thing the individual had messaged me.
-
Interested in searching for unknown malicious software? Our team in Microsoft Research is hiring. The position can be fully remote.
-
Detected a C2 framework in RAM today with velociraptor. Dumped the process memory with velo, created a zignature with radare2.
Never thought I'd ever reach that level...
Blogpost and velo artifact incoming :blobsmile:
#velociraptor #radare2 #detection #c2 #MemoryForensics #DFIR
-
Memory mounting with MemProcFS? This changes everything...
Our Luke Davis dives into MemProcFS in our latest blog, exploring how this tool has transformed memory forensics. MemProcFS allows memory dumps to be mounted and browsed like file systems, making complex memory structures easy to analyse. 💻
Using MemProcFS, investigators can:
Quickly analyse suspicious processes, like tracking Excel launching malicious code
Monitor network connections tied to ransomware groups and other threats
Explore advanced features like memory timelines and registry browsing to trace system activity and investigate security breaches 🔍
This post is a must-read for anyone delving into digital forensics or curious about memory mounting: 🔗https://www.pentestpartners.com/security-blog/mounting-memory-with-memprocfs-for-advanced-memory-forensics/
#MemoryForensics #MemProcFS #DigitalForensics #Cybersecurity #MalwareAnalysis #Infosec
-
In our latest blog, Luke Davis, Head of DFIR, explores the role of memory forensics in cyber investigations.🕵️♂️
Discover how analysing a system's RAM can uncover critical volatile data, such as running processes, encryption keys, network connections, and real-time user activity—evidence often missed by traditional disk forensics.
Learn how this approach helps detect malware, recover hidden data, and identify unauthorised access for a deeper understanding of cyber incidents.
👉 Read the full blog here: https://www.pentestpartners.com/security-blog/investigating-volatile-data-with-advanced-memory-forensics-tools-part-1/
🔜 Stay tuned for part two, where Luke dives into the innovative MemProcFS tool and how it revolutionises memory analysis.
#DFIR #MemoryForensics #DigitalForensics #CyberSecurity #IncidentResponse #ForensicTools #CyberInvestigations #InfoSec -
Proud to announce that I will be teaching a course on Memory Forensics at @defcon in Vegas this summer! 🥳
#DFIR #memoryforensics #training #defcon #vegas
https://training.defcon.org/products/jamie-levy-windows-memory-forensics-dctlv2024
-
@volexity's consistently observes Iranian-origin #APT group CharmingCypress innovate ways to persistently pursue targets. This blog post reviews the group's phishing tactics & malware + how to investigate attacks with Volexity Volcano: https://www.volexity.com/blog/2024/02/13/charmingcypress-innovating-persistence
-
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Finished day 19 yesterday but fell asleep before posting 🤣🤣. Memory forensics is definitely my. Love Volitility 2 and 3. #adventofcyber2023 #adventofcyber #z0ds3c #tryhackme #memoryforensics #cyberforensics #BlueTeam
-
The deadline for the The Volatility Foundation plugin contest deadline is quickly approaching (31 December 2023)!! You have the chance to win over $6000, as well as gain fame, while also helping the community! If you have something that might make a good plugin, don’t forget to submit it!
#dfir #memoryforensics #malware #python
https://volatility-labs.blogspot.com/2023/07/the-11th-annual-volatility-plugin-contest.html?m=1
-
This was a fun trailer we put together for our upcoming #TradecraftTuesday (sound on 🔊). I’ll go over some #memoryforensics techniques and demos live on October 10th at 1PM ET 🐈⬛
👻🎃👻🎃👻🎃👻🎃👻
👻🎃👻🎃👻🎃👻🎃👻
-
Does anyone else have goosebumps? You won't want to miss this month's #TradecraftTuesday presentation as @gleeda shows how to use #memoryforensics to bring your investigations back from the dead!
-
Who is ready to get shady with @gleeda ? You won't want to miss this month's #TradecraftTuesday as Jamie shows you how to use #memoryforensics to bring your investigations back from the dead! 🐈⬛
🎃 👻 🎃 👻🎃 👻🎃 👻
October 10, 2023: 1PM ET
🎃 👻🎃 👻🎃 👻🎃 👻 -
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·MAL: REMnux - The Redux - I have just completed this room! Check it out: https://tryhackme.com/room/malremnuxv2 #tryhackme #ransomware #malware #remnux #memoryforensics #volatility #showcase #malwareanalysis #malremnuxv2 via @RealTryHackMe
-
✅Another #memoryforensics training finished
Thank you for having me @BlueTeamCon 🙏
And thank you to the students for showing up and asking engaging questions! That totally makes teaching so much more fun! 📚
-
There’s still time to sign up for my class on Advanced Memory Forensics at @BlueTeamCon hurry before it fills up!
-
I'm giving a training on #memoryforensics at @BlueTeamCon on August 25th! Sign up soon if you don't want to miss it!
-
I am happy to announce that I will be giving a training at @defcon this summer on Windows Memory Forensics!
This class demonstrates the importance of including Volatile memory in your investigations by covering several attack methodologies that we’ve seen in the field. It also includes an overview of the most widely used memory forensics tool, Volatility, by one of its developers.
Students will leave the class with the ability to investigate modern malware techniques, and quickly answer questions posed in DFIR investigations and help get to root cause of an attack.
https://training.defcon.org/products/jamie-levy-windows-memory-forensics
-
I gave a talk for WiCyS about how I got into #dfir as well as some tips for people who are newly trying to break into this field you can still watch it on demand: https://www.brighttalk.com/webcast/17216/575705?utm_campaign=google-calendar&utm_source=brighttalk-portal&utm_medium=calendar
-
Surprising, but I am unable to find unstripped kernel debug images for Rocky Linux. Does RHEL not make unstripped debugging images available? That's a problem for Volatility3.
Not so much an issue for me right now because this is for a lab and I can just switch to Debian. But it doesn't bode well for memory forensics on modern RedHat OSes.
-
Tune in NOW to hear from our own Marcus Guevara "Is Dead Memory Analysis Dead? Finding Infected Systems through Live Memory Analysis"
-
A brief walk back in time on the progression of #MemoryForensics and capture by @msuiche.
I personally still love a full memory dump, but that's getting so much harder as the size of RAM gets massive.
-
Somebody just uploaded a decent video explaining the differences between simple DLL injection (loading injected code from disk, easily detected by Sysmon/EDR) versus reflective injection (injecting code directly from memory, slightly stealthier) into a victim process.
Either of these, easily detected by tools like Volatility's malfind plugin, or my new favorite, MemProcFS' findevil by @UlfFrisk
-
🦖Day 86 of the
@velocidex
#velociraptor #ArtifactsOfAutumn seriesArtifact: Windows.Memory.Acquisition
Link: https://docs.velociraptor.app/artifact_references/pages/windows.memory.acquisition
----
This artifact leverages Winpmem to acquire a full memory image of the endpoint.
While it is ideal to process and filter data as quickly as possible on the endpoint, in certain instances it may still be beneficial or necessary to obtain a copy of the endpoint's physical memory.
----
This artifact could also be used in conjunction with the offline collector to obtain a memory image with a triage binary as opposed to requiring a client to be connected to the Velociraptor server.
The image could then be processed with your favorite memory analysis framework.
----
That's it for now! Stay tuned to learn about more artifacts! 🦖