Authors: Andrew Case, Hala Ali
DFRWS USA 2025 — “History in the Making” — Jubilee 25th Anniversary
Abstract
Memory forensics—the analysis of volatile memory (RAM)—is an extremely powerful technique for detecting and triaging modern malware. Memory forensics is often a critical component of modern incident response due to the frequent use of memory-only payloads and rootkits that bypass EDRs, hide from live analysis tools, and often leave no file system artifacts. In this workshop, a mix of lectures and hands-on labs provides students with memory forensics knowledge and experience that can be utilized during real-world incident response. A few of the topics that will be covered during this workshop include detection and triage of credential dumping, lateral movement, and memory-only malware loading. By having documentation of these techniques in the slides and gaining hands-on experience analyzing them during the labs, attendees will leave with knowledge that is immediately applicable in real investigations. This workshop is focused on Volatility 3, which is now the standard and supported version of Volatility since its replacing Volatility 2 in April 2025.
Objectives
- The importance of memory forensics
- Applying memory forensics in modern investigations
- Detailed instructions and examples of using Volatility 3
- Hands-on experience performing memory forensics
Provided to students
The students will be provided with a virtual machine, memory samples, a PDF of the slides, and a lab guide that documents the exercises.