Форензика RAM с Volatility

★ 8.4 · security

analyzing-memory-dumps-with-volatility is a Claude Code skill that analyzes RAM memory dumps from compromised systems using the Volatility 3 framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. It supports memory forensics for Windows, Linux, and macOS, covering rootkit detection, fileless malware investigation, and process injection analysis through commands like pslist, psscan, malfind, netscan, hashdump, and YARA scanning. The skill activates for requests involving volatile data examination, RAM analysis, and memory-resident malware investigation where no disk artifacts exist. It requires Volatility 3 with OS-specific symbol tables and a memory dump acquired via WinPmem, LiME, or DumpIt. Incident responders and malware analysts use it to recover encryption keys, cached credentials, and compromise indicators directly from memory images.