Memory Forensics
Find what never touched the disk.
Uncover in-memory threats, fileless malware, and advanced attacker activity that never touches the disk. Learn to capture, analyze, and extract critical evidence from volatile memory across Windows and Linux, turning raw RAM dumps into actionable intelligence for incident response and threat hunting.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations
What Memory Forensics teaches: capture and analyze volatile memory across Windows and Linux to find the fileless malware, injected code, and stolen credentials that never touch disk. The attack-capture-analyze model you'll work, the free toolkit and lab, and how the course is structured. Start here.
Show 8 lessonsHide lessons
- 0.1MF0.1 Running windows.pslist and Reading What Comes BackPreview
- 0.2MF0.2 Why psscan Finds Processes pslist CannotPreview
- 0.3MF0.3 malfind, and Memory With No File Behind ItPreview
- 0.4MF0.4 Handles to lsass, and the Rights That MatterPreview
- 0.5MF0.5 netscan, and the Process That Owned the ConnectionPreview
- 0.6MF0.6 When Volatility Returns Nothing: the Symbol TablePreview
- 0.7MF0.7 Building the Lab and Capturing Your First Memory ImagePreview
- 0.8MF0.8 Interactive: Triage a Memory Image You Have Not SeenPreview
Acquisition as a standard IR step, not a specialist exception. The acquisition problem and smear, WinPmem on Windows, LiME and AVML on Linux, hypervisor capture, pagefile and swap, verification and the acquisition record, smear measurement, anti-acquisition, and the clean baselines the rest of the course compares against.
Show 9 lessonsHide lessons
- 1.1MF1.1 The Acquisition Problem
- 1.2MF1.2 Windows Acquisition with WinPmem
- 1.3MF1.3 Linux Acquisition with LiME and AVML
- 1.4MF1.4 Hypervisor-Based Acquisition
- 1.5MF1.5 Pagefile and Swap as Memory-Adjacent Evidence
- 1.6MF1.6 Acquisition Verification and Integrity
- 1.7MF1.7 Smear Detection and Acquisition Quality
- 1.8MF1.8 Anti-Acquisition Techniques
- 1.9MF1.9 Interactive: Decide the Acquisition
Phase 2: Windows Memory Analysis
The first transient-artifact category in depth. Run a reflective injection against your lab, capture it cleanly, and find it with converging evidence. The process abstraction, VAD tree, protection metadata, the four-line finding method, the replacement techniques the additive workflow misses, and extracting the injected code.
Show 9 lessonsHide lessons
- 2.1MF2.1 Process Abstraction
- 2.2MF2.2 Virtual Memory and Page Tables
- 2.3MF2.3 VAD Tree Fundamentals
- 2.4MF2.4 Executing the Attack
- 2.5MF2.5 Acquiring the Compromised Capture
- 2.6MF2.6 VAD Analysis of the Injected Region
- 2.7MF2.7 Hollowing and Doppelgänging
- 2.8MF2.8 Extracting the Injected Code
- 2.9MF2.9 Interactive Hunt: Injections
Detecting and proving credential theft from a captured image. The LSASS authentication architecture, NTLM hashes and Kerberos tickets, the exposure assessment, Credential Guard's partial protection, the memory signatures that prove a tool read LSASS, and the non-LSASS sources that widen the blast radius.
Show 9 lessonsHide lessons
- 3.1MF3.1 LSASS and the Authentication Architecture
- 3.2MF3.2 Producing the Three Credential-Theft Trails
- 3.3MF3.3 Capturing and Verifying a Credential-Theft Image
- 3.4MF3.4 Extracting Credentials and Building the Exposure Assessment
- 3.5MF3.5 Kerberos Tickets and the Blast Radius of a Stolen TGT
- 3.6MF3.6 Credential Guard and the Partial-Exposure Assessment
- 3.7MF3.7 Memory Signatures of Credential-Theft Tools
- 3.8MF3.8 Non-LSASS Credential Sources in Memory
- 3.9MF3.9 The Credential Hunt: Three Hosts, Three Different Problems
Investigating malware that lives only in memory. Why fileless attacks defeat disk forensics, how PowerShell delivers and reflectively loads a payload, and how to prove the load, extract and identify the payload, recover the C2 configuration, and build a timeline, all from a memory image that is the only evidence there is.
Show 9 lessonsHide lessons
- 4.1MF4.1 The Fileless Malware Problem
- 4.2MF4.2 PowerShell as an Attack Vehicle
- 4.3MF4.3 Executing the Attack
- 4.4MF4.4 Capturing Post-Attack Memory
- 4.5MF4.5 PowerShell Process Memory Analysis
- 4.6MF4.6 Extracting the In-Memory Payload
- 4.7MF4.7 C2 Configuration Extraction
- 4.8MF4.8 PowerShell Event Log Correlation
- 4.9MF4.9 Interactive: The Fileless Hunt
Finding the mechanisms attackers install to survive a reboot. Scheduled tasks across their three artifact locations, WMI event subscriptions in the framework repository, and registry persistence, all read from the authoritative in-memory copy that a tampered disk cannot match, because the active session's evidence dies at reboot but persistence is built to outlast it.
Show 9 lessonsHide lessons
- 5.1MF5.1 Persistence as an Attacker Investment
- 5.2MF5.2 Scheduled Tasks in Memory
- 5.3MF5.3 WMI Event Subscriptions
- 5.4MF5.4 Executing the Attack
- 5.5MF5.5 Capturing Post-Persistence Memory
- 5.6MF5.6 Analyzing the Scheduled Task
- 5.7MF5.7 Analyzing WMI Event Subscriptions
- 5.8MF5.8 Registry in Memory
- 5.9MF5.9 Interactive: The Persistence Hunt
When the attacker stops being a tenant of the system and becomes a co-owner of the kernel. Loading a driver, registering callbacks, and unlinking from the lists enumeration trusts, met by the offline analysis that reads the pool the kernel cannot fake: driver detection, callback attribution, system-call-table checks, and the DKOM detection floor.
Show 9 lessonsHide lessons
- 6.1MF6.1 Crossing into Kernel Space
- 6.2MF6.2 The Driver List, and What It Hides
- 6.3MF6.3 Executing the Attack
- 6.4MF6.4 Capturing the Compromised Host
- 6.5MF6.5 Finding the Hidden Driver
- 6.6MF6.6 Callback Analysis
- 6.7MF6.7 System Call Table Hooks
- 6.8MF6.8 DKOM and the Detection Floor
- 6.9MF6.9 Interactive: The Kernel-Rootkit Hunt
Phase 3: Linux Memory Analysis
Work a two-stage Linux intrusion in memory on SRV-NGE-MCR-APP01: an SSH brute force into a sudo misconfiguration to root and a credential harvest, then an LKM rootkit that hooks getdents64 to hide a process. Capture at both stages and read what each left behind, task_struct enumeration, bash history from the heap, credential recovery, module list versus slab scan, and syscall-table integrity, then detect the eBPF variant the LKM checks miss.
Show 9 lessonsHide lessons
- 7.1MF7.1 Linux Memory Architecture
- 7.2MF7.2 The SSH-to-Root Chain and the Four Artifacts It Leaves
- 7.3MF7.3 Acquiring the Live Host, and Proving the Image Resolves
- 7.4MF7.4 Reading the User-Space Intrusion
- 7.5MF7.5 Recovering Every Credential the Attacker Reached
- 7.6MF7.6 The Kernel Rootkit
- 7.7MF7.7 Detecting the LKM Rootkit
- 7.8MF7.8 The eBPF Rootkit That Leaves the Syscall Table Clean
- 7.9MF7.9 The Linux Kernel Hunt, Unguided
Phase 4: Integration & Capstone
Build a defensible timeline from your MF2-MF7 captures. Classify every timestamp by who wrote it, corroborate against event logs, the MFT and the perimeter, measure clock skew before ordering anything across hosts, and read manipulation as evidence rather than as a ruined timeline.
Show 9 lessonsHide lessons
- 8.1MF8.1 Classifying a Timestamp Before It Becomes an Anchor
- 8.2MF8.2 Building the Timeline When the Image Is All You Have
- 8.3MF8.3 Corroborating an Anchor Against the Event Log, and Reading the Gap
- 8.4MF8.4 When Memory and the Disk Disagree About a File
- 8.5MF8.5 The Witness Outside the Host
- 8.6MF8.6 A Shared Indicator Is Not a Path
- 8.7MF8.7 Assembling the Timeline Others Will Act On
- 8.8MF8.8 The Clock the Attacker Moved
- 8.9MF8.9 Building the Timeline Unguided
Take one intrusion from alert to defensible report: predict artifacts before capturing, place three checkpoints against decay, read each stage as a delta, merge uneven evidence without flattening it, and write for readers who will never see an image.
Show 10 lessonsHide lessons
- 9.1MF9.1 The Six Questions, and Why Chaining Changes the Analysis
- 9.2MF9.2 Running the Chain So the Evidence Is Legible
- 9.3MF9.3 Verifying Three Captures and Differencing Them
- 9.4MF9.4 Reading the First Checkpoint as the Opening of a Chain
- 9.5MF9.5 The Token Mismatch and the Handle That Dates It
- 9.6MF9.6 Persistence, Staging, and the Stage Where Lineage Breaks
- 9.7MF9.7 Merging Four Stages Without Averaging Their Confidence
- 9.8MF9.8 Writing for Readers Who Will Never See an Image
- 9.9MF9.9 Reviewing the Report Against the Brief You Wrote First
- 9.10MF9.10 Working an Intrusion You Did Not Run
Phase 0: Course Resources
The lookup layer: every command the course teaches, grouped by what you are trying to establish.
Show 1 lessonHide lessons
Show 1 lessonHide lessons
Show 1 lessonHide lessons
Show 10 lessonsHide lessons
- 1Injected Code in a Trusted Process
- 2Credential Theft With No Dump File
- 3A PowerShell Command With No File On Disk
- 4Persistence That Survived A Reboot
- 5A Driver That Is Not In The Driver List
- 6Root On A Linux Web Server
- 7Building The Timeline That Ties It Together
- 8Triage: A Capture You Know Nothing About
- 9The Capture That Went Wrong
- 10The Negative Result
Detonation procedures. Each produces the artifact a module teaches you to find, so you analyze evidence whose ground truth you already know.
Resources for practicing memory forensics and using it at work: an open-source DFIR toolkit, the forensic lab, the detection library, response playbooks, and guided investigations.
External sources this course draws on: tooling documentation, research, standards and community memory forensics material.
Course Completion
Memory Forensics end-of-course exam: a three-phase simulation testing whether you can apply the method to a case the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Memory Forensics course delivers hands-on expertise to capture, examine, and interpret volatile memory from live systems and memory dumps. You'll master industry-standard tools and techniques to detect stealthy threats that traditional disk-based forensics cannot see. Learn how to:
By the end, you'll capture and analyze volatile memory the way a working DFIR analyst does, recover evidence that disk forensics cannot, and feed it into your team's detection and response.
How this course works
Memory holds what disk never recorded, and it holds it for as long as the machine stays up. This course runs the same loop for every technique it investigates.
1. Acquire before you decide it matters. Memory is the most volatile evidence you can take and the decision to capture it is made under time pressure with incomplete information. Capture, then triage.
2. Establish what normal looks like on this system. Process trees, loaded modules, network connections. Anomaly detection in memory is comparison, and without a baseline every unfamiliar service looks suspicious.
3. Read the artifact the technique cannot avoid. Injection has to allocate and write. Credential theft has to read a specific process. Reason from what the technique requires rather than from what the tool is named.
4. Corroborate against disk and log. A memory finding on its own is a strong lead. The same activity in a log or on disk, with times that agree, is a conclusion.
5. Build the timeline across sources. Memory tells you what was true at capture. Disk and logs tell you how it got that way, and the intrusion is the sequence rather than the snapshot.
What this course assumes
No minimum experience and no prerequisite course. Process structures, virtual memory and the acquisition model are explained from the ground up.
What makes it go faster: a machine you can capture memory from and enough disk to hold the image. Not required for the reading, and required for the exercises: you capture your own images, which is the first skill the course teaches rather than an overhead it imposes.
What this course does not cover: reverse engineering, disk forensics in depth, and network investigation. Those are separate courses, and memory analysis is strongest when it corroborates them rather than replaces them.
Who this course is for
You're a SOC analyst, incident responder, threat hunter, security engineer, or digital forensics professional who wants to work the investigations disk forensics cannot. This course is designed for you if you want to:
In short, if you want to work memory the way a DFIR specialist does and run the investigations disk forensics cannot, this course is for you.
What you'll learn
By the end of this Memory Forensics course you will be able to:
Key course takeaways
Lab Pack: Attack, Capture, Analyze
Included: 3 VM setup scripts, 7 attack playbooks, PoC kernel driver and LKM rootkit source code with build instructions, 33 exercises (Standard/Hard/Expert), 10 verification scripts, 10 HTML walkthroughs, 6 documentation templates.
Not included by design: Memory images (you capture your own), pre-compiled binaries (you build from source), analysis tools (install per Lab Setup Guide). Capturing memory and building PoC tools from source are skills, not overhead.
Things you need to know
What are the prerequisites for this course?
None. Every memory forensics concept is explained at first use, including the process and virtual-memory structures the tools report on. Comfort at a command line and prior incident-response or disk-forensics experience will make you faster, and neither is assumed.
What are the device requirements?
A device with at least 16 GB of RAM (32 GB recommended for running multiple VMs simultaneously). You will need a hypervisor (VMware Workstation, VirtualBox, or similar) to run the attack lab environment: a Windows target VM, a Linux target VM, and a Kali attacker VM. Approximately 80 GB of free disk space for VM images and memory captures.
How will the course benefit your career?
Memory forensics is one of the most advanced and in-demand specializations in digital forensics and incident response. Organizations increasingly face fileless malware, in-memory attacks, and threats that leave no trace on disk. Analysts who can capture and interpret volatile memory are critical to detecting these threats.
This course builds the skills needed for senior DFIR roles, memory forensics specialist positions, threat hunting teams, and advanced SOC functions. The ability to analyze volatile evidence sets you apart from cybersecurity professionals limited to disk-based forensics.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.
Attack tools: Metasploit, Mimikatz, and PoC rootkits are for educational use in isolated lab environments only. Running them against unauthorized systems is illegal.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.