Memory and disk forensics
Answer the three questions a memory image is asked - what was running, what was typed, what was on disk - and know why a scan beats a list.
By the end you can
- Distinguish a raw memory image from a crash dump or hibernation file before analysing it
- Explain why psscan finds processes pslist cannot, and what that costs in validation
- Recover command lines from a Windows image, including the UTF-16 problem
- Locate and carve a registry hive out of a dump and read persistence from it
- Read ext, FAT and NTFS structures well enough to recover a deleted or resident file
- Read the boot record chain and say where a bootkit would have to live
1. Read
Memory dump triage: what was running, what was typed, what was on disk
A raw memory image answers three questions and you should ask them in that order. Why psscan beats pslist for a challenge, where command lines actually live, and how to get from a dump to a registry hive.
Disk image forensics: partitions, deleted files, and slack
A forensics challenge hands you a raw disk image and no map. The layered way to take it apart - partition table, filesystem, deleted files, unallocated space, and slack - so the flag stops hiding in the gaps between files.
The boot process as a target: MBR, VBR, and bootkits
Before the OS loads, a chain of tiny programs runs from the first sectors of the disk - and a forensics challenge can hide a flag, or a bootkit, right there. How the boot chain works and how to analyse the sectors it lives in.
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- Memory dump, disk image and registry hive analysis
Scan a Windows memory image for processes, command lines, file objects and registry hives - and read ext4, FAT, NTFS $MFT and registry hives - entirely in the browser.
Open it in the workspace - Strings extractor for binaries and blobs
Pull printable ASCII and UTF-16 strings out of any file, filtered by length, with flag-pattern highlighting.
Open it in the workspace - File type identifier by magic bytes
Drop a file and identify what it really is from its signature, regardless of extension. Also finds file headers embedded inside other files.
Open it in the workspace - Hex viewer and hexdump
Inspect any file byte by byte with a side-by-side hex and ASCII view, offsets, and structure highlighting.
Open it in the workspace - Timestamp converter (Unix, ISO, FILETIME, HFS+)
Convert between Unix seconds and milliseconds, ISO 8601, local time, and the non-standard epochs used by Windows, macOS, and Flask.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 26 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Trusting a process list from a compromised machine. The list is a linked list the malware can edit; a scan for the structure signature is not.
- Running strings on a Windows dump without -el and concluding there is nothing there. Most of what you want is UTF-16.
- Deleting is not erasing, but neither is it permanent. A recovered file needs its metadata source stated, because a carved file and an MFT-recovered file are different claims.
- Reading empty plugin output as a clean machine. Every plugin depends on matching the image to the right kernel build or symbol set, and the mismatch shows up as silence rather than as an error.
- Treating the page file and unallocated space as out of scope. A process that exited leaves its strings in both, and 'what was typed' often survives nowhere else on the image.
Checkpoint
Given a raw Windows memory image, produce the process tree, identify the process that should not be there, and recover the command line it was started with.
Teaching note
The UTF-16 point lands better as a demonstration than as a statement: run strings without -el on a dump, get nothing, run it with -el, and get the whole command history. Students who see that once never forget it.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 6, Forensic Image Acquisition
Practical Forensic Imaging - Bruce Nikkel
How the image you are handed was made, and what that decides about what can still be recovered from it.
Chapter 8, Special Image Access Topics
Practical Forensic Imaging - Bruce Nikkel
Encrypted volumes, RAID sets and virtual machine disks - the cases where the image will not simply mount.
Chapter 5, Operating System Boot Process Essentials
Rootkits and Bootkits - Alex Matrosov, Eugene Rodionov, and Sergey Bratus
The boot chain in the detail the MBR and VBR challenges assume you already have.
Chapter 18, Approaches to Analyzing Hidden Filesystems
Rootkits and Bootkits - Alex Matrosov, Eugene Rodionov, and Sergey Bratus
What to do when the filesystem itself is the thing lying to you.
Every book the curriculum cites has a page in the library.