logo

Mounting memory with MemProcFS for advanced memory forensics

ID: db9770c9-9726-572b-9df6-ecda950829de

STIX ID: report--db9770c9-9726-572b-9df6-ecda950829de

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-10-31

Date Updated: 2026-03-24

Author: Luke Davis

...
...

This report is a practical memory forensics write-up demonstrating how MemProcFS, alongside Volatility 2/3, can mount and analyze Windows RAM as a file system to uncover artifacts such as processes, handles, registry hives, and timelines. In a lab scenario, the author identifies suspicious Excel activity and a network connection to 185.141.63.120 (associated with the Conti ransomware), providing concrete IOCs (including a file hash) and showcasing workflows like netstat parsing, parent/child PID tracing, and automated timeline generation via MemProcFS’s forensic mode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.