Memory Forensics Basics

intermediate 40 min 3 tasksSubscription

Acquire a memory image from a compromised Windows host and analyze it with Volatility 3: list processes, hunt for code injection with malfind, inspect network connections, and identify an injected process that disk artifacts never reveal.

This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.

Part of these paths

Unlock this lab

Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.

Updated 2026-06-15