Memory forensics Challenges This repository contains a list of memory forensics challenges that I've been solving using the volatility tool for getting more hands-on experience in this forensic field. I'm working on writing brief write-ups for each challenge that I've been solving during the last 2 months. My idea is to keep solving memory forensics challenges and to update this repository from time to time.
I've chosen challenges from the following websites:
The Volatility Foundation The volatility foundation is a non-profit organisation that promotes and maintains Volatility, the popular open-source tool for memory forensics. On their Github, you can find a good list of some memory samples from different sources such as CTFs, books or malware samples.
CCN-CERT ATENEA ATENEA is a CTF platform hosted by the CCN-CERT, the Spanish Government CERT. ATENEA contains different types of challenges such as memory forensics, reversing or cryptography.
Cyber Defenders
Cyberdefenders is a great training platform for BlueTeams to test their CyberDefense skills. The platform contains many free challenges of different types such as Malicious Documents, Reversing, Memory Forensics, etc.
These write-ups are less explained than the previous ones. I didn't include the flag of each answer. Instead, I've written the needed steps using Volatility or other tools such as PeepPDF, foremost or grep.