Please enable JavaScript.
Coggle requires JavaScript to display documents.
🧠01 Foundations of Memory Forensics (Linux Enterprise) - Coggle Diagram
🧠01 Foundations of Memory Forensics (Linux Enterprise)
📚 What is Memory Forensics
Definition
Memory Forensics is the process of acquiring, preserving, analyzing, and interpreting the contents of Random Access Memory (RAM) from a running Linux system to investigate security incidents.
Purpose
Detect malware
Detect ransomware
Detect rootkits
Detect fileless malware
Recover encryption keys
Recover attacker activities
Investigate compromised servers
Perform Incident Response
Collect evidence for legal investigations
Enterprise Usage
Security Operations Center (SOC)
Digital Forensics and Incident Response (DFIR)
Threat Hunting
Malware Analysis
Cloud Security
Critical Infrastructure
Financial Institutions
Government Agencies
Industrial Control Systems
Data Centers
💾 Understanding Memory (RAM)
Definition
Random Access Memory is temporary volatile storage used by the operating system while it is running.
Characteristics
Volatile Memory
Data disappears after shutdown.
Fast Memory
CPU accesses RAM much faster than disks.
Active Storage
Stores currently running programs and kernel information.
Dynamic
Contents constantly change while the system is running.
Contains
Running Processes
Loaded Kernel
Device Drivers
Network Connections
Logged-in Users
Shared Libraries
Passwords
Encryption Keys
Malware
Rootkits
Command History
Environment Variables
Open Files
File Cache
Page Cache
DNS Cache
Process Memory
Heap
Stack
🖥 Linux Memory Architecture
Physical Memory
Definition
Actual RAM installed in the computer.
Example
16 Gigabytes RAM
Virtual Memory
Definition
Every process believes it owns its own memory space.
Managed By
Linux Kernel
Advantages
Process Isolation
Security
Memory Protection
Swap Memory
Definition
Disk space used when RAM becomes full.
Files
Swap Partition
Swap File
Commands
swapon --show
free -h
Page
Definition
Smallest memory block managed by Linux.
Typical Size
4096 Bytes
Commands
getconf PAGE_SIZE
Memory Page Types
Anonymous Pages
File-backed Pages
Shared Pages
Cached Pages
⚙ Linux Kernel Memory Management
Linux Kernel
Definition
Core component controlling CPU Memory Devices Filesystem Networking Security
Responsibilities
Process Scheduling
Memory Allocation
Page Allocation
Virtual Memory Management
Hardware Communication
System Calls
Important Directories
/proc
/sys
/dev
/boot
/lib/modules
Important Files
/proc/meminfo
/proc/vmstat
/proc/slabinfo
/proc/iomem
/proc/kallsyms
/proc/buddyinfo
/proc/pagetypeinfo
📂 Process Memory Layout
Process
Definition
Running instance of a program.
Components
Text Segment
Executable machine code.
Data Segment
Initialized global variables.
BSS Segment
Uninitialized variables.
Heap
Dynamically allocated memory.
Stack
Function calls
Local variables
Shared Libraries
Common libraries loaded into memory.
Memory Mapped Files
Files mapped directly into memory.
Commands
ps aux
top
htop
pmap ProcessID
cat /proc/ProcessID/maps
cat /proc/ProcessID/smaps
🏢 Enterprise Memory Acquisition
Goal
Capture RAM without altering evidence.
Acquisition Types
Live Memory Acquisition
Hypervisor Snapshot
Cloud Snapshot
Virtual Machine Snapshot
Enterprise Tools
LiME
Linux Memory Extractor
AVML
Azure Virtual Machine Memory Dumper
fmem
WinPMEM
DumpIt
Output
Raw Memory Dump
Lime Format
ELF Format
Storage
External Disk
Network Storage
Evidence Server
📁 Memory Dump
Definition
Complete copy of RAM.
Typical Extensions
.lime
.raw
.mem
.bin
.img
Enterprise Storage
Immutable Storage
Evidence Repository
Write Once Storage
🔬 Memory Analysis
Goals
Identify Malware
Recover Processes
Detect Hidden Processes
Detect Rootkits
Analyze Network Connections
Recover Credentials
Detect Persistence
Identify Code Injection
Framework
Volatility 3
Typical Workflow
Acquire Memory
Verify Hash
Preserve Evidence
Analyze Offline
Generate Report
🔐 Evidence Integrity
Purpose
Ensure evidence has not changed.
Hash Algorithms
SHA256
SHA512
Commands
sha256sum memory.lime
sha512sum memory.lime
Documentation
Chain of Custody
Investigator Name
Acquisition Time
Hostname
Case Number
📊 Linux Information Sources
Proc Filesystem
Definition
Virtual filesystem exposing kernel and process information.
Directory
/proc
Sys Filesystem
Definition
Virtual filesystem exposing kernel devices.
Directory
/sys
Dev Directory
Definition
Device files.
Directory
/dev
Commands
ls /proc
ls /sys
ls /dev
🔍 What Investigators Search For
Suspicious Processes
Hidden Processes
Zombie Processes
Orphan Processes
Malicious Shared Libraries
Code Injection
Shell History
Environment Variables
SSH Keys
Open Files
Network Sockets
Reverse Shells
Kernel Modules
Rootkits
Cron Jobs
Malware Configuration
Encryption Keys
Browser Credentials
Containers
Kubernetes Secrets
🌐 Enterprise Investigation Workflow
Step 1
Detect Security Incident
Step 2
Isolate System
Step 3
Capture Memory
Step 4
Calculate Hash
Step 5
Preserve Original Dump
Step 6
Create Working Copy
Step 7
Analyze Using Volatility 3
Step 8
Recover Indicators of Compromise
Step 9
Correlate With
SIEM
Firewall Logs
Endpoint Detection and Response
DNS Logs
Authentication Logs
Cloud Logs
Step 10
Produce DFIR Report
📂 Important Linux Paths
Memory Information
/proc/meminfo
/proc/vmstat
/proc/iomem
/proc/slabinfo
/proc/buddyinfo
/proc/pagetypeinfo
Process Information
/proc
/proc/PID
/proc/PID/maps
/proc/PID/smaps
/proc/PID/status
/proc/PID/environ
/proc/PID/fd
Kernel Information
/boot
/boot/vmlinuz
/boot/System.map
/lib/modules
Log Files
/var/log
/var/log/messages
/var/log/syslog
/var/log/auth.log
/var/log/kern.log
🛠 Enterprise Commands
Memory Information
free -h
vmstat
cat /proc/meminfo
cat /proc/vmstat
Process Investigation
ps aux
top
htop
pstree
pmap PID
Memory Maps
cat /proc/PID/maps
cat /proc/PID/smaps
Open Files
lsof
Network
ss -tulnp
ip addr
ip route
Kernel
uname -a
lsmod
modinfo ModuleName
dmesg
Hash Verification
sha256sum memory.lime
sha512sum memory.lime
🎯 Enterprise Learning Roadmap
Foundation
Linux Memory Architecture
Virtual Memory
Process Memory
Kernel Memory
Memory Allocation
Acquisition
LiME
AVML
Evidence Preservation
Analysis
Volatility 3
Process Analysis
Network Analysis
Kernel Analysis
Malware Analysis
Advanced Topics
Rootkit Detection
Fileless Malware
Reflective Loading
Process Hollowing
Shared Memory Abuse
Kernel Object Analysis
Container Memory Forensics
Cloud Memory Forensics