daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

volatility.md (13109B)


      1 ---
      2 title: "Volatility 3"
      3 description: "Volatility 3 Windows memory forensics: processes, network, injection, hashes and plugin workflow."
      4 category: dfir
      5 tags: [dfir, memory-forensics, malware]
      6 tools: [Volatility 3]
      7 difficulty: advanced
      8 updated: "2026-08-09"
      9 source: "vault:DFIR/Volitility3 .md"
     10 ---
     11 
     12 # Volatility 3
     13 
     14 Windows memory forensics cheat sheet.
     15 
     16 ## Basic Command Structure
     17 
     18 ```bash
     19 # Standard syntax
     20 vol -f <memory.raw> <plugin>
     21 
     22 # With options
     23 vol -f memory.raw -o output/ -r json windows.pslist
     24 
     25 # Plugin-specific help
     26 vol windows.pslist -h
     27 ```
     28 
     29 ### Key Differences from Volatility 2
     30 
     31 - NO `--profile` needed (auto-detection)
     32 - Plugin namespace: `windows.plugin_name`
     33 - Faster execution
     34 - Python 3.8+ required
     35 - Unified output formats
     36 
     37 ---
     38 
     39 ## Complete Plugin Enumeration Workflow
     40 
     41 ### Phase 1: System Identification
     42 
     43 ```bash
     44 # Verify image and get OS info
     45 vol -f memory.raw windows.info
     46 
     47 # Output: OS version, architecture, kernel base, system time
     48 ```
     49 
     50 ### Phase 2: Process Analysis
     51 
     52 #### Process Enumeration (Multiple Methods)
     53 
     54 ```bash
     55 # Active processes (linked list traversal)
     56 vol -f memory.raw windows.pslist
     57 
     58 # Hidden/terminated processes (pool scanning)
     59 vol -f memory.raw windows.psscan
     60 
     61 # Process hierarchy tree
     62 vol -f memory.raw windows.pstree
     63 
     64 # Cross-reference detection (rootkit hunting)
     65 vol -f memory.raw windows.psxview
     66 ```
     67 
     68 #### Process Details
     69 
     70 ```bash
     71 # Command-line arguments
     72 vol -f memory.raw windows.cmdline
     73 vol -f memory.raw windows.cmdline --pid 1234
     74 
     75 # Command history from cmd.exe
     76 vol -f memory.raw windows.cmdscan
     77 
     78 # Console buffers
     79 vol -f memory.raw windows.consoles
     80 
     81 # Environment variables
     82 vol -f memory.raw windows.envars --pid 1234
     83 
     84 # Process privileges
     85 vol -f memory.raw windows.privileges.Privs
     86 
     87 # Process SIDs
     88 vol -f memory.raw windows.getsids
     89 
     90 # Process threads
     91 vol -f memory.raw windows.threads
     92 vol -f memory.raw windows.threads --pid 1234
     93 
     94 # Suspended threads
     95 vol -f memory.raw windows.suspended_threads
     96 
     97 # Suspicious threads
     98 vol -f memory.raw windows.suspicious_threads
     99 
    100 # Debug registers
    101 vol -f memory.raw windows.debugregisters
    102 
    103 # Orphaned kernel threads
    104 vol -f memory.raw windows.orphan_kernel_threads
    105 ```
    106 
    107 #### DLL Analysis
    108 
    109 ```bash
    110 # Loaded DLLs per process
    111 vol -f memory.raw windows.dlllist
    112 vol -f memory.raw windows.dlllist --pid 1234
    113 
    114 # DLL load verification (detect DLL injection)
    115 vol -f memory.raw windows.ldrmodules
    116 
    117 # Unloaded modules
    118 vol -f memory.raw windows.unloadedmodules
    119 ```
    120 
    121 #### Handles
    122 
    123 ```bash
    124 # Open handles (files, registry, mutexes, etc.)
    125 vol -f memory.raw windows.handles
    126 vol -f memory.raw windows.handles --pid 1234
    127 ```
    128 
    129 ### Phase 3: Network Analysis
    130 
    131 ```bash
    132 # Network connections (TCP/UDP) - Vista+
    133 vol -f memory.raw windows.netscan
    134 
    135 # Alternative: netstat (Vista+)
    136 vol -f memory.raw windows.netstat
    137 ```
    138 
    139 **Output:** Local/Remote addresses, PIDs, state, protocol, timestamps.
    140 
    141 ### Phase 4: File System Analysis
    142 
    143 ```bash
    144 # Scan for FILE_OBJECT structures
    145 vol -f memory.raw windows.filescan
    146 
    147 # Dump cached files
    148 vol -f memory.raw -o output/ windows.dumpfiles
    149 vol -f memory.raw -o output/ windows.dumpfiles --pid 1234
    150 vol -f memory.raw -o output/ windows.dumpfiles --virtaddr 0x12345678
    151 vol -f memory.raw -o output/ windows.dumpfiles --physaddr 0xabcdef
    152 
    153 # MFT entries scanning
    154 vol -f memory.raw windows.mftscan.MFTScan
    155 
    156 # Alternate Data Streams (ADS)
    157 vol -f memory.raw windows.mftscan.ADS
    158 
    159 # Symbolic links
    160 vol -f memory.raw windows.symlinkscan
    161 ```
    162 
    163 ### Phase 5: Registry Analysis
    164 
    165 ```bash
    166 # List registry hives
    167 vol -f memory.raw windows.registry.hivelist
    168 
    169 # Scan for hives
    170 vol -f memory.raw windows.registry.hivescan
    171 
    172 # Print registry keys
    173 vol -f memory.raw windows.registry.printkey
    174 vol -f memory.raw windows.registry.printkey --key "Software\\Microsoft\\Windows\\CurrentVersion\\Run"
    175 
    176 # UserAssist (tracks executed programs)
    177 vol -f memory.raw windows.registry.userassist
    178 
    179 # Certificates
    180 vol -f memory.raw windows.registry.certificates.Certificates
    181 
    182 # Hooked registry handlers
    183 vol -f memory.raw windows.registry.getcellroutine
    184 ```
    185 
    186 ### Phase 6: Malware Detection
    187 
    188 #### Code Injection Detection
    189 
    190 ```bash
    191 # Find injected code
    192 vol -f memory.raw windows.malfind
    193 
    194 # Hollow processes
    195 vol -f memory.raw windows.hollowprocesses
    196 
    197 # Process ghosting
    198 vol -f memory.raw windows.processghosting
    199 
    200 # Direct system calls (EDR bypass)
    201 vol -f memory.raw windows.direct_system_calls
    202 
    203 # Indirect system calls (EDR bypass)
    204 vol -f memory.raw windows.indirect_system_calls
    205 
    206 # Unhooked system calls (EDR bypass)
    207 vol -f memory.raw windows.unhooked_system_calls
    208 ```
    209 
    210 #### Kernel Hooks & Rootkits
    211 
    212 ```bash
    213 # Kernel callbacks
    214 vol -f memory.raw windows.callbacks.Callbacks
    215 
    216 # SSDT (System Service Descriptor Table)
    217 vol -f memory.raw windows.ssdt.SSDT
    218 
    219 # Driver IRP hooks
    220 vol -f memory.raw windows.driverirp.DriverIrp
    221 
    222 # Hidden drivers
    223 vol -f memory.raw windows.drivermodule.DriverModule
    224 
    225 # Skeleton Key malware detection
    226 vol -f memory.raw windows.skeleton_key_check.Skeleton_Key_Check
    227 
    228 # Kernel timers
    229 vol -f memory.raw windows.timers.Timers
    230 ```
    231 
    232 #### YARA Scanning
    233 
    234 ```bash
    235 # Scan process memory with YARA
    236 vol -f memory.raw windows.vadyarascan --yara-file rules.yar
    237 vol -f memory.raw windows.vadyarascan --yara-rules "rule test { strings: $a = \"malware\" condition: $a }"
    238 
    239 # Scan entire memory
    240 vol -f memory.raw yarascan.YaraScan --yara-file rules.yar
    241 
    242 # Regex scanning
    243 vol -f memory.raw windows.vadregexscan --pattern "https?://[a-zA-Z0-9]+"
    244 ```
    245 
    246 #### Import Address Table (IAT) Analysis
    247 
    248 ```bash
    249 vol -f memory.raw windows.iat.IAT --pid 1234
    250 ```
    251 
    252 ### Phase 7: Memory Dumps
    253 
    254 ```bash
    255 # Dump process memory
    256 vol -f memory.raw -o output/ windows.memmap --dump --pid 1234
    257 
    258 # Dump PE executables
    259 vol -f memory.raw -o output/ windows.pedump.PEDump --pid 1234
    260 
    261 # Memory map
    262 vol -f memory.raw windows.memmap --pid 1234
    263 
    264 # VAD (Virtual Address Descriptor) information
    265 vol -f memory.raw windows.vadinfo --pid 1234
    266 
    267 # Walk VAD tree
    268 vol -f memory.raw windows.vadwalk --pid 1234
    269 ```
    270 
    271 ### Phase 8: Windows Services
    272 
    273 ```bash
    274 # List services (doubly-linked list)
    275 vol -f memory.raw windows.svclist.SvcList
    276 
    277 # Scan for services (pool scanning)
    278 vol -f memory.raw windows.svcscan.SvcScan
    279 
    280 # Compare methods (rootkit detection)
    281 vol -f memory.raw windows.svcdiff.SvcDiff
    282 
    283 # Service SIDs
    284 vol -f memory.raw windows.getservicesids.GetServiceSIDs
    285 ```
    286 
    287 ### Phase 9: Scheduled Tasks
    288 
    289 ```bash
    290 vol -f memory.raw windows.scheduled_tasks.ScheduledTasks
    291 ```
    292 
    293 ### Phase 10: Credential Extraction
    294 
    295 ```bash
    296 # Password hashes
    297 vol -f memory.raw windows.hashdump.Hashdump
    298 
    299 # LSA secrets
    300 vol -f memory.raw windows.lsadump.Lsadump
    301 
    302 # Cached domain credentials
    303 vol -f memory.raw windows.cachedump.Cachedump
    304 
    305 # TrueCrypt passphrases
    306 vol -f memory.raw windows.truecrypt.Passphrase
    307 ```
    308 
    309 ### Phase 11: Driver Analysis
    310 
    311 ```bash
    312 # Loaded kernel modules
    313 vol -f memory.raw windows.modules.Modules
    314 
    315 # Scan for drivers (finds hidden)
    316 vol -f memory.raw windows.driverscan.DriverScan
    317 
    318 # Module scanning
    319 vol -f memory.raw windows.modscan.ModScan
    320 
    321 # Device tree
    322 vol -f memory.raw windows.devicetree.DeviceTree
    323 
    324 # KPCR structures
    325 vol -f memory.raw windows.kpcrs.KPCRs
    326 ```
    327 
    328 ### Phase 12: Forensic Artifacts
    329 
    330 ```bash
    331 # AmCache
    332 vol -f memory.raw windows.amcache.Amcache
    333 
    334 # ShimCache
    335 vol -f memory.raw windows.shimcachemem.ShimcacheMem
    336 
    337 # Big page pools
    338 vol -f memory.raw windows.bigpools.BigPools
    339 
    340 # Master Boot Record scanning
    341 vol -f memory.raw windows.mbrscan.MBRScan
    342 
    343 # Job links
    344 vol -f memory.raw windows.joblinks.JobLinks
    345 
    346 # Sessions
    347 vol -f memory.raw windows.sessions.Sessions
    348 
    349 # Crash dump info
    350 vol -f memory.raw windows.crashinfo.Crashinfo
    351 
    352 # PE symbols
    353 vol -f memory.raw windows.pe_symbols.PESymbols
    354 
    355 # Version info
    356 vol -f memory.raw windows.verinfo.VerInfo
    357 
    358 # Statistics
    359 vol -f memory.raw windows.statistics.Statistics
    360 ```
    361 
    362 ### Phase 13: Mutexes & Synchronization
    363 
    364 ```bash
    365 # Scan for mutexes
    366 vol -f memory.raw windows.mutantscan.MutantScan
    367 ```
    368 
    369 ### Phase 14: Timeline Analysis
    370 
    371 ```bash
    372 # Generate timeline from all plugins
    373 vol -f memory.raw timeliner.Timeliner
    374 ```
    375 
    376 ---
    377 
    378 ## New Plugins in Volatility 3 (v2.7–2.26)
    379 
    380 ### EDR Bypass Detection
    381 
    382 ```bash
    383 windows.direct_system_calls       # Direct syscall technique
    384 windows.indirect_system_calls     # Indirect syscall technique
    385 windows.unhooked_system_calls     # Unhooked syscall detection
    386 ```
    387 
    388 ### Advanced Malware Detection
    389 
    390 ```bash
    391 windows.hollowprocesses           # Process hollowing detection
    392 windows.processghosting           # Process ghosting technique
    393 windows.suspended_threads         # Find suspended threads
    394 windows.suspicious_threads        # Identify suspicious threads
    395 windows.orphan_kernel_threads     # Orphaned kernel threads
    396 ```
    397 
    398 ### Command History & Console
    399 
    400 ```bash
    401 windows.cmdscan                   # Command history scanning
    402 windows.consoles                  # Console buffer extraction
    403 ```
    404 
    405 ### Registry & Forensics
    406 
    407 ```bash
    408 windows.amcache.Amcache           # AmCache parsing
    409 windows.scheduled_tasks           # Scheduled tasks
    410 windows.registry.getcellroutine   # Registry hook detection
    411 windows.shimcachemem              # ShimCache from memory
    412 windows.debugregisters            # Hardware breakpoint detection
    413 ```
    414 
    415 ### Import Address Table
    416 
    417 ```bash
    418 windows.iat.IAT                   # IAT extraction and analysis
    419 ```
    420 
    421 ### Process Cross-Reference
    422 
    423 ```bash
    424 windows.psxview                   # Multi-method process detection
    425 ```
    426 
    427 ### Regex & Advanced Scanning
    428 
    429 ```bash
    430 windows.vadregexscan              # Regex pattern scanning in VADs
    431 ```
    432 
    433 ---
    434 
    435 ## Output Formats
    436 
    437 ```bash
    438 # JSON output
    439 vol -f memory.raw -r json windows.pslist > output.json
    440 
    441 # CSV output
    442 vol -f memory.raw -r csv windows.pslist > output.csv
    443 
    444 # Pretty formatted
    445 vol -f memory.raw -r pretty windows.pslist
    446 
    447 # JSONL (line-delimited JSON)
    448 vol -f memory.raw -r jsonl windows.netscan
    449 
    450 # Save to file
    451 vol -f memory.raw windows.pslist > pslist.txt
    452 ```
    453 
    454 ---
    455 
    456 ## Advanced Tips & Tricks
    457 
    458 ### 1. Filtering & Targeting
    459 
    460 ```bash
    461 # Target specific PID
    462 vol -f memory.raw windows.pslist --pid 1234
    463 vol -f memory.raw windows.dlllist --pid 1234
    464 
    465 # Multiple PIDs (plugin dependent)
    466 vol -f memory.raw windows.handles --pid 1234 --pid 5678
    467 ```
    468 
    469 ### 2. Parallel Processing
    470 
    471 ```bash
    472 vol -f memory.raw --parallelism processes windows.psscan
    473 ```
    474 
    475 ### 3. Verbosity for Debugging
    476 
    477 ```bash
    478 # Increase verbosity to troubleshoot
    479 vol -f memory.raw -vvv windows.info
    480 ```
    481 
    482 ### 4. Offline Mode
    483 
    484 ```bash
    485 # Disable online symbol lookups
    486 vol -f memory.raw --offline windows.pslist
    487 ```
    488 
    489 ### 5. Configuration Files
    490 
    491 ```bash
    492 # Use config file for repeated analysis
    493 vol -c config.json windows.pslist
    494 
    495 # Save configuration
    496 vol -f memory.raw --save-config analysis.json windows.pslist
    497 ```
    498 
    499 ### 6. Combining Outputs
    500 
    501 ```bash
    502 # Run multiple plugins and save all
    503 for plugin in pslist pstree netscan filescan; do
    504     vol -f memory.raw windows.$plugin > ${plugin}_output.txt
    505 done
    506 ```
    507 
    508 ### 7. Hunting for Specific Artifacts
    509 
    510 ```bash
    511 # Find specific string in process memory
    512 vol -f memory.raw windows.strings | grep -i "password"
    513 
    514 # Search for IP addresses
    515 vol -f memory.raw windows.netscan | grep "192.168"
    516 
    517 # Find processes without parent
    518 vol -f memory.raw windows.pstree | grep "PPID: 0"
    519 ```
    520 
    521 ### 8. Memory Dump Extraction
    522 
    523 ```bash
    524 # Dump specific process
    525 vol -f memory.raw -o dumps/ windows.memmap --dump --pid 1234
    526 
    527 # Dump all files
    528 vol -f memory.raw -o files/ windows.dumpfiles
    529 
    530 # Dump executable only
    531 vol -f memory.raw -o exe/ windows.pedump --pid 1234
    532 ```
    533 
    534 ---
    535 
    536 ## Malware Analysis Workflow
    537 
    538 ### Step 1: Initial Triage
    539 
    540 ```bash
    541 vol -f memory.raw windows.info
    542 vol -f memory.raw windows.pslist
    543 vol -f memory.raw windows.pstree
    544 vol -f memory.raw windows.netscan
    545 ```
    546 
    547 ### Step 2: Identify Suspicious Processes
    548 
    549 Look for:
    550 - Processes with no parent (PPID: 0)
    551 - Misspelled system processes
    552 - Unusual paths (not in System32/Program Files)
    553 - Processes with network connections
    554 - Short-lived processes (in psscan but not pslist)
    555 
    556 ### Step 3: Deep Dive on Suspicious Process
    557 
    558 ```bash
    559 PID=<suspicious_pid>
    560 vol -f memory.raw windows.cmdline --pid $PID
    561 vol -f memory.raw windows.dlllist --pid $PID
    562 vol -f memory.raw windows.handles --pid $PID
    563 vol -f memory.raw windows.envars --pid $PID
    564 vol -f memory.raw windows.malfind --pid $PID
    565 vol -f memory.raw windows.vadinfo --pid $PID
    566 ```
    567 
    568 ### Step 4: Code Injection Detection
    569 
    570 ```bash
    571 vol -f memory.raw windows.malfind
    572 vol -f memory.raw windows.hollowprocesses
    573 vol -f memory.raw windows.ldrmodules
    574 vol -f memory.raw windows.direct_system_calls
    575 vol -f memory.raw windows.indirect_system_calls
    576 ```
    577 
    578 ### Step 5: Persistence Mechanisms
    579 
    580 ```bash
    581 vol -f memory.raw windows.registry.printkey --key "Software\\Microsoft\\Windows\\CurrentVersion\\Run"
    582 vol -f memory.raw windows.registry.userassist
    583 vol -f memory.raw windows.scheduled_tasks
    584 vol -f memory.raw windows.svcscan
    585 ```
    586 
    587 ### Step 6: Dump & Analyze
    588 
    589 ```bash
    590 vol -f memory.raw -o output/ windows.memmap --dump --pid $PID
    591 vol -f memory.raw -o output/ windows.pedump --pid $PID
    592 ```
    593 
    594 ---
    595 
    596 ## Rootkit Detection Checklist
    597 
    598 ```bash
    599 # 1. Hidden processes
    600 vol -f memory.raw windows.psxview
    601 
    602 # 2. Hidden drivers
    603 vol -f memory.raw windows.drivermodule
    604 
    605 # 3. Kernel hooks
    606 vol -f memory.raw windows.ssdt
    607 vol -f memory.raw windows.callbacks
    608 ```