# Memory Forensics Starter Kit

Authorized use only: analyze memory images that were acquired with owner consent
or under a valid incident-response/legal authority.

## Setup
```bash
python3 -m venv .venv
source .venv/bin/activate
pip install volatility3
vol -h
```

## Baseline Commands
Replace `memory.raw` with the acquired image.

```bash
vol -f memory.raw windows.info
vol -f memory.raw windows.pslist.PsList
vol -f memory.raw windows.pstree.PsTree
vol -f memory.raw windows.cmdline.CmdLine
vol -f memory.raw windows.netscan.NetScan
vol -f memory.raw windows.dlllist.DllList --pid <pid>
vol -f memory.raw windows.malfind.Malfind
vol -f memory.raw windows.filescan.FileScan
vol -f memory.raw windows.registry.hivelist.HiveList
```

## Linux Triage Pattern
```bash
vol -f memory.raw linux.banners.Banners
vol -f memory.raw linux.pslist.PsList
vol -f memory.raw linux.lsof.Lsof
vol -f memory.raw linux.netfilter.Netfilter
```

## Evidence Table
| Plugin | Key output | Triage question | Follow-up |
|---|---|---|---|
| `pslist` / `pstree` | Process hierarchy | Unknown or orphaned processes? | Check command line and parent PID |
| `cmdline` | Process arguments | Suspicious script or interpreter use? | Map to user and filesystem path |
| `netscan` | Network sockets | Unexpected remote endpoints? | Pivot to firewall/proxy logs |
| `malfind` | Injected memory regions | Executable private pages? | Dump and hash region |
| `filescan` | File objects | Deleted or staged files? | Extract for static analysis |

## Reporting Notes
- Record Volatility version and plugin names.
- Preserve terminal output or redirect to immutable case files.
- Treat findings as leads until corroborated by disk, network, or log artifacts.
