volatility.md (13109B)
1 --- 2 title: "Volatility 3" 3 description: "Volatility 3 Windows memory forensics: processes, network, injection, hashes and plugin workflow." 4 category: dfir 5 tags: [dfir, memory-forensics, malware] 6 tools: [Volatility 3] 7 difficulty: advanced 8 updated: "2026-08-09" 9 source: "vault:DFIR/Volitility3 .md" 10 --- 11 12 # Volatility 3 13 14 Windows memory forensics cheat sheet. 15 16 ## Basic Command Structure 17 18 ```bash 19 # Standard syntax 20 vol -f <memory.raw> <plugin> 21 22 # With options 23 vol -f memory.raw -o output/ -r json windows.pslist 24 25 # Plugin-specific help 26 vol windows.pslist -h 27 ``` 28 29 ### Key Differences from Volatility 2 30 31 - NO `--profile` needed (auto-detection) 32 - Plugin namespace: `windows.plugin_name` 33 - Faster execution 34 - Python 3.8+ required 35 - Unified output formats 36 37 --- 38 39 ## Complete Plugin Enumeration Workflow 40 41 ### Phase 1: System Identification 42 43 ```bash 44 # Verify image and get OS info 45 vol -f memory.raw windows.info 46 47 # Output: OS version, architecture, kernel base, system time 48 ``` 49 50 ### Phase 2: Process Analysis 51 52 #### Process Enumeration (Multiple Methods) 53 54 ```bash 55 # Active processes (linked list traversal) 56 vol -f memory.raw windows.pslist 57 58 # Hidden/terminated processes (pool scanning) 59 vol -f memory.raw windows.psscan 60 61 # Process hierarchy tree 62 vol -f memory.raw windows.pstree 63 64 # Cross-reference detection (rootkit hunting) 65 vol -f memory.raw windows.psxview 66 ``` 67 68 #### Process Details 69 70 ```bash 71 # Command-line arguments 72 vol -f memory.raw windows.cmdline 73 vol -f memory.raw windows.cmdline --pid 1234 74 75 # Command history from cmd.exe 76 vol -f memory.raw windows.cmdscan 77 78 # Console buffers 79 vol -f memory.raw windows.consoles 80 81 # Environment variables 82 vol -f memory.raw windows.envars --pid 1234 83 84 # Process privileges 85 vol -f memory.raw windows.privileges.Privs 86 87 # Process SIDs 88 vol -f memory.raw windows.getsids 89 90 # Process threads 91 vol -f memory.raw windows.threads 92 vol -f memory.raw windows.threads --pid 1234 93 94 # Suspended threads 95 vol -f memory.raw windows.suspended_threads 96 97 # Suspicious threads 98 vol -f memory.raw windows.suspicious_threads 99 100 # Debug registers 101 vol -f memory.raw windows.debugregisters 102 103 # Orphaned kernel threads 104 vol -f memory.raw windows.orphan_kernel_threads 105 ``` 106 107 #### DLL Analysis 108 109 ```bash 110 # Loaded DLLs per process 111 vol -f memory.raw windows.dlllist 112 vol -f memory.raw windows.dlllist --pid 1234 113 114 # DLL load verification (detect DLL injection) 115 vol -f memory.raw windows.ldrmodules 116 117 # Unloaded modules 118 vol -f memory.raw windows.unloadedmodules 119 ``` 120 121 #### Handles 122 123 ```bash 124 # Open handles (files, registry, mutexes, etc.) 125 vol -f memory.raw windows.handles 126 vol -f memory.raw windows.handles --pid 1234 127 ``` 128 129 ### Phase 3: Network Analysis 130 131 ```bash 132 # Network connections (TCP/UDP) - Vista+ 133 vol -f memory.raw windows.netscan 134 135 # Alternative: netstat (Vista+) 136 vol -f memory.raw windows.netstat 137 ``` 138 139 **Output:** Local/Remote addresses, PIDs, state, protocol, timestamps. 140 141 ### Phase 4: File System Analysis 142 143 ```bash 144 # Scan for FILE_OBJECT structures 145 vol -f memory.raw windows.filescan 146 147 # Dump cached files 148 vol -f memory.raw -o output/ windows.dumpfiles 149 vol -f memory.raw -o output/ windows.dumpfiles --pid 1234 150 vol -f memory.raw -o output/ windows.dumpfiles --virtaddr 0x12345678 151 vol -f memory.raw -o output/ windows.dumpfiles --physaddr 0xabcdef 152 153 # MFT entries scanning 154 vol -f memory.raw windows.mftscan.MFTScan 155 156 # Alternate Data Streams (ADS) 157 vol -f memory.raw windows.mftscan.ADS 158 159 # Symbolic links 160 vol -f memory.raw windows.symlinkscan 161 ``` 162 163 ### Phase 5: Registry Analysis 164 165 ```bash 166 # List registry hives 167 vol -f memory.raw windows.registry.hivelist 168 169 # Scan for hives 170 vol -f memory.raw windows.registry.hivescan 171 172 # Print registry keys 173 vol -f memory.raw windows.registry.printkey 174 vol -f memory.raw windows.registry.printkey --key "Software\\Microsoft\\Windows\\CurrentVersion\\Run" 175 176 # UserAssist (tracks executed programs) 177 vol -f memory.raw windows.registry.userassist 178 179 # Certificates 180 vol -f memory.raw windows.registry.certificates.Certificates 181 182 # Hooked registry handlers 183 vol -f memory.raw windows.registry.getcellroutine 184 ``` 185 186 ### Phase 6: Malware Detection 187 188 #### Code Injection Detection 189 190 ```bash 191 # Find injected code 192 vol -f memory.raw windows.malfind 193 194 # Hollow processes 195 vol -f memory.raw windows.hollowprocesses 196 197 # Process ghosting 198 vol -f memory.raw windows.processghosting 199 200 # Direct system calls (EDR bypass) 201 vol -f memory.raw windows.direct_system_calls 202 203 # Indirect system calls (EDR bypass) 204 vol -f memory.raw windows.indirect_system_calls 205 206 # Unhooked system calls (EDR bypass) 207 vol -f memory.raw windows.unhooked_system_calls 208 ``` 209 210 #### Kernel Hooks & Rootkits 211 212 ```bash 213 # Kernel callbacks 214 vol -f memory.raw windows.callbacks.Callbacks 215 216 # SSDT (System Service Descriptor Table) 217 vol -f memory.raw windows.ssdt.SSDT 218 219 # Driver IRP hooks 220 vol -f memory.raw windows.driverirp.DriverIrp 221 222 # Hidden drivers 223 vol -f memory.raw windows.drivermodule.DriverModule 224 225 # Skeleton Key malware detection 226 vol -f memory.raw windows.skeleton_key_check.Skeleton_Key_Check 227 228 # Kernel timers 229 vol -f memory.raw windows.timers.Timers 230 ``` 231 232 #### YARA Scanning 233 234 ```bash 235 # Scan process memory with YARA 236 vol -f memory.raw windows.vadyarascan --yara-file rules.yar 237 vol -f memory.raw windows.vadyarascan --yara-rules "rule test { strings: $a = \"malware\" condition: $a }" 238 239 # Scan entire memory 240 vol -f memory.raw yarascan.YaraScan --yara-file rules.yar 241 242 # Regex scanning 243 vol -f memory.raw windows.vadregexscan --pattern "https?://[a-zA-Z0-9]+" 244 ``` 245 246 #### Import Address Table (IAT) Analysis 247 248 ```bash 249 vol -f memory.raw windows.iat.IAT --pid 1234 250 ``` 251 252 ### Phase 7: Memory Dumps 253 254 ```bash 255 # Dump process memory 256 vol -f memory.raw -o output/ windows.memmap --dump --pid 1234 257 258 # Dump PE executables 259 vol -f memory.raw -o output/ windows.pedump.PEDump --pid 1234 260 261 # Memory map 262 vol -f memory.raw windows.memmap --pid 1234 263 264 # VAD (Virtual Address Descriptor) information 265 vol -f memory.raw windows.vadinfo --pid 1234 266 267 # Walk VAD tree 268 vol -f memory.raw windows.vadwalk --pid 1234 269 ``` 270 271 ### Phase 8: Windows Services 272 273 ```bash 274 # List services (doubly-linked list) 275 vol -f memory.raw windows.svclist.SvcList 276 277 # Scan for services (pool scanning) 278 vol -f memory.raw windows.svcscan.SvcScan 279 280 # Compare methods (rootkit detection) 281 vol -f memory.raw windows.svcdiff.SvcDiff 282 283 # Service SIDs 284 vol -f memory.raw windows.getservicesids.GetServiceSIDs 285 ``` 286 287 ### Phase 9: Scheduled Tasks 288 289 ```bash 290 vol -f memory.raw windows.scheduled_tasks.ScheduledTasks 291 ``` 292 293 ### Phase 10: Credential Extraction 294 295 ```bash 296 # Password hashes 297 vol -f memory.raw windows.hashdump.Hashdump 298 299 # LSA secrets 300 vol -f memory.raw windows.lsadump.Lsadump 301 302 # Cached domain credentials 303 vol -f memory.raw windows.cachedump.Cachedump 304 305 # TrueCrypt passphrases 306 vol -f memory.raw windows.truecrypt.Passphrase 307 ``` 308 309 ### Phase 11: Driver Analysis 310 311 ```bash 312 # Loaded kernel modules 313 vol -f memory.raw windows.modules.Modules 314 315 # Scan for drivers (finds hidden) 316 vol -f memory.raw windows.driverscan.DriverScan 317 318 # Module scanning 319 vol -f memory.raw windows.modscan.ModScan 320 321 # Device tree 322 vol -f memory.raw windows.devicetree.DeviceTree 323 324 # KPCR structures 325 vol -f memory.raw windows.kpcrs.KPCRs 326 ``` 327 328 ### Phase 12: Forensic Artifacts 329 330 ```bash 331 # AmCache 332 vol -f memory.raw windows.amcache.Amcache 333 334 # ShimCache 335 vol -f memory.raw windows.shimcachemem.ShimcacheMem 336 337 # Big page pools 338 vol -f memory.raw windows.bigpools.BigPools 339 340 # Master Boot Record scanning 341 vol -f memory.raw windows.mbrscan.MBRScan 342 343 # Job links 344 vol -f memory.raw windows.joblinks.JobLinks 345 346 # Sessions 347 vol -f memory.raw windows.sessions.Sessions 348 349 # Crash dump info 350 vol -f memory.raw windows.crashinfo.Crashinfo 351 352 # PE symbols 353 vol -f memory.raw windows.pe_symbols.PESymbols 354 355 # Version info 356 vol -f memory.raw windows.verinfo.VerInfo 357 358 # Statistics 359 vol -f memory.raw windows.statistics.Statistics 360 ``` 361 362 ### Phase 13: Mutexes & Synchronization 363 364 ```bash 365 # Scan for mutexes 366 vol -f memory.raw windows.mutantscan.MutantScan 367 ``` 368 369 ### Phase 14: Timeline Analysis 370 371 ```bash 372 # Generate timeline from all plugins 373 vol -f memory.raw timeliner.Timeliner 374 ``` 375 376 --- 377 378 ## New Plugins in Volatility 3 (v2.7–2.26) 379 380 ### EDR Bypass Detection 381 382 ```bash 383 windows.direct_system_calls # Direct syscall technique 384 windows.indirect_system_calls # Indirect syscall technique 385 windows.unhooked_system_calls # Unhooked syscall detection 386 ``` 387 388 ### Advanced Malware Detection 389 390 ```bash 391 windows.hollowprocesses # Process hollowing detection 392 windows.processghosting # Process ghosting technique 393 windows.suspended_threads # Find suspended threads 394 windows.suspicious_threads # Identify suspicious threads 395 windows.orphan_kernel_threads # Orphaned kernel threads 396 ``` 397 398 ### Command History & Console 399 400 ```bash 401 windows.cmdscan # Command history scanning 402 windows.consoles # Console buffer extraction 403 ``` 404 405 ### Registry & Forensics 406 407 ```bash 408 windows.amcache.Amcache # AmCache parsing 409 windows.scheduled_tasks # Scheduled tasks 410 windows.registry.getcellroutine # Registry hook detection 411 windows.shimcachemem # ShimCache from memory 412 windows.debugregisters # Hardware breakpoint detection 413 ``` 414 415 ### Import Address Table 416 417 ```bash 418 windows.iat.IAT # IAT extraction and analysis 419 ``` 420 421 ### Process Cross-Reference 422 423 ```bash 424 windows.psxview # Multi-method process detection 425 ``` 426 427 ### Regex & Advanced Scanning 428 429 ```bash 430 windows.vadregexscan # Regex pattern scanning in VADs 431 ``` 432 433 --- 434 435 ## Output Formats 436 437 ```bash 438 # JSON output 439 vol -f memory.raw -r json windows.pslist > output.json 440 441 # CSV output 442 vol -f memory.raw -r csv windows.pslist > output.csv 443 444 # Pretty formatted 445 vol -f memory.raw -r pretty windows.pslist 446 447 # JSONL (line-delimited JSON) 448 vol -f memory.raw -r jsonl windows.netscan 449 450 # Save to file 451 vol -f memory.raw windows.pslist > pslist.txt 452 ``` 453 454 --- 455 456 ## Advanced Tips & Tricks 457 458 ### 1. Filtering & Targeting 459 460 ```bash 461 # Target specific PID 462 vol -f memory.raw windows.pslist --pid 1234 463 vol -f memory.raw windows.dlllist --pid 1234 464 465 # Multiple PIDs (plugin dependent) 466 vol -f memory.raw windows.handles --pid 1234 --pid 5678 467 ``` 468 469 ### 2. Parallel Processing 470 471 ```bash 472 vol -f memory.raw --parallelism processes windows.psscan 473 ``` 474 475 ### 3. Verbosity for Debugging 476 477 ```bash 478 # Increase verbosity to troubleshoot 479 vol -f memory.raw -vvv windows.info 480 ``` 481 482 ### 4. Offline Mode 483 484 ```bash 485 # Disable online symbol lookups 486 vol -f memory.raw --offline windows.pslist 487 ``` 488 489 ### 5. Configuration Files 490 491 ```bash 492 # Use config file for repeated analysis 493 vol -c config.json windows.pslist 494 495 # Save configuration 496 vol -f memory.raw --save-config analysis.json windows.pslist 497 ``` 498 499 ### 6. Combining Outputs 500 501 ```bash 502 # Run multiple plugins and save all 503 for plugin in pslist pstree netscan filescan; do 504 vol -f memory.raw windows.$plugin > ${plugin}_output.txt 505 done 506 ``` 507 508 ### 7. Hunting for Specific Artifacts 509 510 ```bash 511 # Find specific string in process memory 512 vol -f memory.raw windows.strings | grep -i "password" 513 514 # Search for IP addresses 515 vol -f memory.raw windows.netscan | grep "192.168" 516 517 # Find processes without parent 518 vol -f memory.raw windows.pstree | grep "PPID: 0" 519 ``` 520 521 ### 8. Memory Dump Extraction 522 523 ```bash 524 # Dump specific process 525 vol -f memory.raw -o dumps/ windows.memmap --dump --pid 1234 526 527 # Dump all files 528 vol -f memory.raw -o files/ windows.dumpfiles 529 530 # Dump executable only 531 vol -f memory.raw -o exe/ windows.pedump --pid 1234 532 ``` 533 534 --- 535 536 ## Malware Analysis Workflow 537 538 ### Step 1: Initial Triage 539 540 ```bash 541 vol -f memory.raw windows.info 542 vol -f memory.raw windows.pslist 543 vol -f memory.raw windows.pstree 544 vol -f memory.raw windows.netscan 545 ``` 546 547 ### Step 2: Identify Suspicious Processes 548 549 Look for: 550 - Processes with no parent (PPID: 0) 551 - Misspelled system processes 552 - Unusual paths (not in System32/Program Files) 553 - Processes with network connections 554 - Short-lived processes (in psscan but not pslist) 555 556 ### Step 3: Deep Dive on Suspicious Process 557 558 ```bash 559 PID=<suspicious_pid> 560 vol -f memory.raw windows.cmdline --pid $PID 561 vol -f memory.raw windows.dlllist --pid $PID 562 vol -f memory.raw windows.handles --pid $PID 563 vol -f memory.raw windows.envars --pid $PID 564 vol -f memory.raw windows.malfind --pid $PID 565 vol -f memory.raw windows.vadinfo --pid $PID 566 ``` 567 568 ### Step 4: Code Injection Detection 569 570 ```bash 571 vol -f memory.raw windows.malfind 572 vol -f memory.raw windows.hollowprocesses 573 vol -f memory.raw windows.ldrmodules 574 vol -f memory.raw windows.direct_system_calls 575 vol -f memory.raw windows.indirect_system_calls 576 ``` 577 578 ### Step 5: Persistence Mechanisms 579 580 ```bash 581 vol -f memory.raw windows.registry.printkey --key "Software\\Microsoft\\Windows\\CurrentVersion\\Run" 582 vol -f memory.raw windows.registry.userassist 583 vol -f memory.raw windows.scheduled_tasks 584 vol -f memory.raw windows.svcscan 585 ``` 586 587 ### Step 6: Dump & Analyze 588 589 ```bash 590 vol -f memory.raw -o output/ windows.memmap --dump --pid $PID 591 vol -f memory.raw -o output/ windows.pedump --pid $PID 592 ``` 593 594 --- 595 596 ## Rootkit Detection Checklist 597 598 ```bash 599 # 1. Hidden processes 600 vol -f memory.raw windows.psxview 601 602 # 2. Hidden drivers 603 vol -f memory.raw windows.drivermodule 604 605 # 3. Kernel hooks 606 vol -f memory.raw windows.ssdt 607 vol -f memory.raw windows.callbacks 608 ```