Memory Forensics Basics
intermediate 40 min 3 tasksSubscription
Acquire a memory image from a compromised Windows host and analyze it with Volatility 3: list processes, hunt for code injection with malfind, inspect network connections, and identify an injected process that disk artifacts never reveal.
This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.
Part of these paths
Unlock this lab
Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.
Updated 2026-06-15