Skip to content
All modules
AdvancedModule 19 of 27120 minutes

Memory and disk forensics

Answer the three questions a memory image is asked - what was running, what was typed, what was on disk - and know why a scan beats a list.

Assumes16. File forensics and carving

By the end you can

  • Distinguish a raw memory image from a crash dump or hibernation file before analysing it
  • Explain why psscan finds processes pslist cannot, and what that costs in validation
  • Recover command lines from a Windows image, including the UTF-16 problem
  • Locate and carve a registry hive out of a dump and read persistence from it
  • Read ext, FAT and NTFS structures well enough to recover a deleted or resident file
  • Read the boot record chain and say where a bootkit would have to live

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 26 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Trusting a process list from a compromised machine. The list is a linked list the malware can edit; a scan for the structure signature is not.
  • Running strings on a Windows dump without -el and concluding there is nothing there. Most of what you want is UTF-16.
  • Deleting is not erasing, but neither is it permanent. A recovered file needs its metadata source stated, because a carved file and an MFT-recovered file are different claims.
  • Reading empty plugin output as a clean machine. Every plugin depends on matching the image to the right kernel build or symbol set, and the mismatch shows up as silence rather than as an error.
  • Treating the page file and unallocated space as out of scope. A process that exited leaves its strings in both, and 'what was typed' often survives nowhere else on the image.

Checkpoint

Given a raw Windows memory image, produce the process tree, identify the process that should not be there, and recover the command line it was started with.

Teaching note

The UTF-16 point lands better as a demonstration than as a statement: run strings without -el on a dump, get nothing, run it with -el, and get the whole command history. Students who see that once never forget it.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.