tag

memory-forensics

11 indexed skills · max 10 per page

skills (11)

detecting-process-injection-techniques

mukul975/Anthropic-Cybersecurity-Skills · detecting-process-injection-techniques

0

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection.

analyzing-linux-kernel-rootkits

mukul975/Anthropic-Cybersecurity-Skills · analyzing-linux-kernel-rootkits

0

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.

conducting-memory-forensics-with-volatility

mukul975/Anthropic-Cybersecurity-Skills · conducting-memory-forensics-with-volatility

0

Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.

performing-memory-forensics-with-volatility3-plugins

mukul975/Anthropic-Cybersecurity-Skills · performing-memory-forensics-with-volatility3-plugins

0

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

performing-memory-forensics-with-volatility3

mukul975/Anthropic-Cybersecurity-Skills · performing-memory-forensics-with-volatility3

0

Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.

analyzing-memory-dumps-with-volatility

mukul975/Anthropic-Cybersecurity-Skills · analyzing-memory-dumps-with-volatility

0

Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis, volatile data examination, process injection detection, or memory-resident malware investigation.

detecting-rootkit-activity

mukul975/Anthropic-Cybersecurity-Skills · detecting-rootkit-activity

0

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.

extracting-credentials-from-memory-dump

mukul975/Anthropic-Cybersecurity-Skills · extracting-credentials-from-memory-dump

0

Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.

analyzing-memory-forensics-with-lime-and-volatility

mukul975/Anthropic-Cybersecurity-Skills · analyzing-memory-forensics-with-lime-and-volatility

0

Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.

analyzing-heap-spray-exploitation

mukul975/Anthropic-Cybersecurity-Skills · analyzing-heap-spray-exploitation

0

Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.

prevpage 1 / 2next