Memory Forensics

Find what never touched the disk.

Uncover in-memory threats, fileless malware, and advanced attacker activity that never touches the disk. Learn to capture, analyze, and extract critical evidence from volatile memory across Windows and Linux, turning raw RAM dumps into actionable intelligence for incident response and threat hunting.

Included with Specialist, from $29/month, or $289/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Detect process injection, fileless malware, and credential theft directly inside memory dumps
✓Simulate real-world attacks and instantly analyze the volatile artifacts they leave behind
✓Extract actionable Indicators of Compromise (IOCs) from purely in-memory evidence that never touches disk
✓Perform deep forensic analysis on both Windows and Linux memory captures using Volatility 3
✓Reconstruct complete attack timelines and attacker behavior using only volatile memory evidence
FOR502 | Specialist tier | 10 modules across 4 phases | 40 CPE credits | All tools free

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Foundations

Module 1Memory Acquisition

Acquisition as a standard IR step, not a specialist exception. The acquisition problem and smear, WinPmem on Windows, LiME and AVML on Linux, hypervisor capture, pagefile and swap, verification and the acquisition record, smear measurement, anti-acquisition, and the clean baselines the rest of the course compares against.

Show 9 lessonsHide lessons
  1. 1.1MF1.1 The Acquisition Problem
  2. 1.2MF1.2 Windows Acquisition with WinPmem
  3. 1.3MF1.3 Linux Acquisition with LiME and AVML
  4. 1.4MF1.4 Hypervisor-Based Acquisition
  5. 1.5MF1.5 Pagefile and Swap as Memory-Adjacent Evidence
  6. 1.6MF1.6 Acquisition Verification and Integrity
  7. 1.7MF1.7 Smear Detection and Acquisition Quality
  8. 1.8MF1.8 Anti-Acquisition Techniques
  9. 1.9MF1.9 Interactive: Decide the Acquisition

Phase 2: Windows Memory Analysis

Module 2Process Injection

The first transient-artifact category in depth. Run a reflective injection against your lab, capture it cleanly, and find it with converging evidence. The process abstraction, VAD tree, protection metadata, the four-line finding method, the replacement techniques the additive workflow misses, and extracting the injected code.

Show 9 lessonsHide lessons
  1. 2.1MF2.1 Process Abstraction
  2. 2.2MF2.2 Virtual Memory and Page Tables
  3. 2.3MF2.3 VAD Tree Fundamentals
  4. 2.4MF2.4 Executing the Attack
  5. 2.5MF2.5 Acquiring the Compromised Capture
  6. 2.6MF2.6 VAD Analysis of the Injected Region
  7. 2.7MF2.7 Hollowing and Doppelgänging
  8. 2.8MF2.8 Extracting the Injected Code
  9. 2.9MF2.9 Interactive Hunt: Injections
Module 4Fileless Malware

Investigating malware that lives only in memory. Why fileless attacks defeat disk forensics, how PowerShell delivers and reflectively loads a payload, and how to prove the load, extract and identify the payload, recover the C2 configuration, and build a timeline, all from a memory image that is the only evidence there is.

Show 9 lessonsHide lessons
  1. 4.1MF4.1 The Fileless Malware Problem
  2. 4.2MF4.2 PowerShell as an Attack Vehicle
  3. 4.3MF4.3 Executing the Attack
  4. 4.4MF4.4 Capturing Post-Attack Memory
  5. 4.5MF4.5 PowerShell Process Memory Analysis
  6. 4.6MF4.6 Extracting the In-Memory Payload
  7. 4.7MF4.7 C2 Configuration Extraction
  8. 4.8MF4.8 PowerShell Event Log Correlation
  9. 4.9MF4.9 Interactive: The Fileless Hunt
Module 5Persistence Mechanisms

Finding the mechanisms attackers install to survive a reboot. Scheduled tasks across their three artifact locations, WMI event subscriptions in the framework repository, and registry persistence, all read from the authoritative in-memory copy that a tampered disk cannot match, because the active session's evidence dies at reboot but persistence is built to outlast it.

Show 9 lessonsHide lessons
  1. 5.1MF5.1 Persistence as an Attacker Investment
  2. 5.2MF5.2 Scheduled Tasks in Memory
  3. 5.3MF5.3 WMI Event Subscriptions
  4. 5.4MF5.4 Executing the Attack
  5. 5.5MF5.5 Capturing Post-Persistence Memory
  6. 5.6MF5.6 Analyzing the Scheduled Task
  7. 5.7MF5.7 Analyzing WMI Event Subscriptions
  8. 5.8MF5.8 Registry in Memory
  9. 5.9MF5.9 Interactive: The Persistence Hunt
Module 6Kernel-Level Compromise

When the attacker stops being a tenant of the system and becomes a co-owner of the kernel. Loading a driver, registering callbacks, and unlinking from the lists enumeration trusts, met by the offline analysis that reads the pool the kernel cannot fake: driver detection, callback attribution, system-call-table checks, and the DKOM detection floor.

Show 9 lessonsHide lessons
  1. 6.1MF6.1 Crossing into Kernel Space
  2. 6.2MF6.2 The Driver List, and What It Hides
  3. 6.3MF6.3 Executing the Attack
  4. 6.4MF6.4 Capturing the Compromised Host
  5. 6.5MF6.5 Finding the Hidden Driver
  6. 6.6MF6.6 Callback Analysis
  7. 6.7MF6.7 System Call Table Hooks
  8. 6.8MF6.8 DKOM and the Detection Floor
  9. 6.9MF6.9 Interactive: The Kernel-Rootkit Hunt

Phase 3: Linux Memory Analysis

Module 7Linux Attack and Memory Analysis: SSH Compromise and Kernel Rootkit

Work a two-stage Linux intrusion in memory on SRV-NGE-MCR-APP01: an SSH brute force into a sudo misconfiguration to root and a credential harvest, then an LKM rootkit that hooks getdents64 to hide a process. Capture at both stages and read what each left behind, task_struct enumeration, bash history from the heap, credential recovery, module list versus slab scan, and syscall-table integrity, then detect the eBPF variant the LKM checks miss.

Show 9 lessonsHide lessons
  1. 7.1MF7.1 Linux Memory Architecture
  2. 7.2MF7.2 The SSH-to-Root Chain and the Four Artifacts It Leaves
  3. 7.3MF7.3 Acquiring the Live Host, and Proving the Image Resolves
  4. 7.4MF7.4 Reading the User-Space Intrusion
  5. 7.5MF7.5 Recovering Every Credential the Attacker Reached
  6. 7.6MF7.6 The Kernel Rootkit
  7. 7.7MF7.7 Detecting the LKM Rootkit
  8. 7.8MF7.8 The eBPF Rootkit That Leaves the Syscall Table Clean
  9. 7.9MF7.9 The Linux Kernel Hunt, Unguided

Phase 4: Integration & Capstone

Phase 0: Course Resources

ResourcesCheatsheets

The lookup layer: every command the course teaches, grouped by what you are trying to establish.

Show 1 lessonHide lessons
  1. 1Cheatsheet
ResourcesCookbooks

Procedures: what you do, in what order, and what each step must produce.

Show 1 lessonHide lessons
  1. 1Cookbook
ResourcesLab Setup

Build the environment that produces the evidence this course analyzes.

Show 1 lessonHide lessons
  1. 1Lab Setup
ResourcesPlaybooks

Detonation procedures. Each produces the artifact a module teaches you to find, so you analyze evidence whose ground truth you already know.

Show 7 lessonsHide lessons
  1. 1Reflective DLL Injection via Meterpreter
  2. 2Mimikatz Credential Theft
  3. 3PowerShell Reflective Loader
  4. 4Scheduled Task and WMI Event Subscription
  5. 5Kernel Driver with Process-Creation Callback
  6. 6SSH Compromise and LKM Rootkit
  7. 7The Full Attack Chain
ResourcesPlayground

Resources for practicing memory forensics and using it at work: an open-source DFIR toolkit, the forensic lab, the detection library, response playbooks, and guided investigations.

ResourcesReferences

External sources this course draws on: tooling documentation, research, standards and community memory forensics material.

Course Completion

CompletionCourse Exam

Memory Forensics end-of-course exam: a three-phase simulation testing whether you can apply the method to a case the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Memory Forensics

Course overview

The Memory Forensics course delivers hands-on expertise to capture, examine, and interpret volatile memory from live systems and memory dumps. You'll master industry-standard tools and techniques to detect stealthy threats that traditional disk-based forensics cannot see. Learn how to:

✓ Acquire and analyze memory from Windows, Linux, and virtual/cloud environments
✓ Extract processes, network connections, credentials and key material, injected code, and attacker artifacts
✓ Identify fileless malware, rootkits, and advanced persistent threats (APTs)
✓ Build repeatable workflows for rapid incident response and deep-dive investigations

By the end, you'll capture and analyze volatile memory the way a working DFIR analyst does, recover evidence that disk forensics cannot, and feed it into your team's detection and response.

How this course works

Memory holds what disk never recorded, and it holds it for as long as the machine stays up. This course runs the same loop for every technique it investigates.

1. Acquire before you decide it matters. Memory is the most volatile evidence you can take and the decision to capture it is made under time pressure with incomplete information. Capture, then triage.

2. Establish what normal looks like on this system. Process trees, loaded modules, network connections. Anomaly detection in memory is comparison, and without a baseline every unfamiliar service looks suspicious.

3. Read the artifact the technique cannot avoid. Injection has to allocate and write. Credential theft has to read a specific process. Reason from what the technique requires rather than from what the tool is named.

4. Corroborate against disk and log. A memory finding on its own is a strong lead. The same activity in a log or on disk, with times that agree, is a conclusion.

5. Build the timeline across sources. Memory tells you what was true at capture. Disk and logs tell you how it got that way, and the intrusion is the sequence rather than the snapshot.

What this course assumes

No minimum experience and no prerequisite course. Process structures, virtual memory and the acquisition model are explained from the ground up.

What makes it go faster: a machine you can capture memory from and enough disk to hold the image. Not required for the reading, and required for the exercises: you capture your own images, which is the first skill the course teaches rather than an overhead it imposes.

What this course does not cover: reverse engineering, disk forensics in depth, and network investigation. Those are separate courses, and memory analysis is strongest when it corroborates them rather than replaces them.

Who this course is for

You're a SOC analyst, incident responder, threat hunter, security engineer, or digital forensics professional who wants to work the investigations disk forensics cannot. This course is designed for you if you want to:

✓ Master volatile memory analysis to uncover threats that never touch the disk
✓ Develop the investigative mindset and technical precision needed to detect fileless malware, rootkits, and advanced in-memory attacks
✓ Turn raw memory captures into clear, actionable intelligence for real-world incident response and threat hunting
✓ Build memory-analysis capability across Windows and Linux

In short, if you want to work memory the way a DFIR specialist does and run the investigations disk forensics cannot, this course is for you.

What you'll learn

By the end of this Memory Forensics course you will be able to:

✓ Capture and analyze volatile memory from live systems and memory dumps across Windows and Linux, including cloud and virtual-machine acquisition
✓ Extract critical artifacts including processes, network connections, credentials and key material, injected code, and attacker footprints
✓ Identify and investigate fileless malware, rootkits, process injection, and advanced persistent threats (APTs) that evade traditional forensics
✓ Apply structured analytical workflows and industry-standard tools to rapidly reconstruct attacker activity
✓ Interpret memory data and write findings that state what the evidence supports and what it does not, which is what survives a challenge
✓ Build repeatable, production-grade memory forensics capabilities that strengthen your organization's detection and response posture

Key course takeaways

✓ Gain production-ready memory forensics skills to detect stealthy, diskless threats that traditional methods cannot see
✓ Run full-scope memory investigations and turn the findings into actionable intelligence for the team
✓ Master the most important volatile artifacts and evidence locations across Windows and Linux
✓ Quickly uncover hidden attacker activity, key material, and in-memory persistence mechanisms
✓ Create repeatable investigative workflows and lab environments that make you highly effective and consistent on the job
✓ Move from disk-based forensics into memory analysis as a working specialism

Lab Pack: Attack, Capture, Analyze

Included: 3 VM setup scripts, 7 attack playbooks, PoC kernel driver and LKM rootkit source code with build instructions, 33 exercises (Standard/Hard/Expert), 10 verification scripts, 10 HTML walkthroughs, 6 documentation templates.

Not included by design: Memory images (you capture your own), pre-compiled binaries (you build from source), analysis tools (install per Lab Setup Guide). Capturing memory and building PoC tools from source are skills, not overhead.

Memory Forensics Lab Pack v2.0
7 attacks · 10 walkthroughs · 33 exercises · PoC source code · report templates
Download Lab Pack (.zip)

Things you need to know

What are the prerequisites for this course?

None. Every memory forensics concept is explained at first use, including the process and virtual-memory structures the tools report on. Comfort at a command line and prior incident-response or disk-forensics experience will make you faster, and neither is assumed.

What are the device requirements?

A device with at least 16 GB of RAM (32 GB recommended for running multiple VMs simultaneously). You will need a hypervisor (VMware Workstation, VirtualBox, or similar) to run the attack lab environment: a Windows target VM, a Linux target VM, and a Kali attacker VM. Approximately 80 GB of free disk space for VM images and memory captures.

How will the course benefit your career?

Memory forensics is one of the most advanced and in-demand specializations in digital forensics and incident response. Organizations increasingly face fileless malware, in-memory attacks, and threats that leave no trace on disk. Analysts who can capture and interpret volatile memory are critical to detecting these threats.

This course builds the skills needed for senior DFIR roles, memory forensics specialist positions, threat hunting teams, and advanced SOC functions. The ability to analyze volatile evidence sets you apart from cybersecurity professionals limited to disk-based forensics.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Attack tools: Metasploit, Mimikatz, and PoC rootkits are for educational use in isolated lab environments only. Running them against unauthorized systems is illegal.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.