Summary

Memory forensics is a great technique to find and extract forensic artifacts from the computer's memory. In addition to using memory forensics for malware investigation, you can use it as part of the malware analysis to gain additional information about the behavior and the characteristics of a malware. This chapter covered different Volatility plugins, which enabled you to gain an understanding of the events that occurred on the comprised system and provided insight into the malware's activity. In the next chapter, we will determine the advanced malware capabilities, using a few more Volatility plugins, and you will understand how to extract forensic artifacts using these plugins.

Get Learning Malware Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.