From transient state to active behaviour

Volatile & Network Analysis

Examine memory and network evidence to understand running processes, active connections, injected code, protocols, and communications.

2analysis routes5practical tools1shared timeline
01

Connect processes to communications

Use both evidence types where possible to test the same explanation.

Stage 1Define the behaviour in question

Record the host, time window, addresses, users, and suspected behaviour before selecting plugins or filters.

Ask: What observable activity would support or challenge the hypothesis?
02

Choose your evidence path

Start with the captured evidence you have, then correlate with the other source when available.

Best matchStart with memory analysis

Examine running state, processes, modules, handles, and connections from a memory image.

03

Build your foundation

Learn what each evidence source represents before choosing analysis techniques.

04

Choose a tool by evidence

Select a starting tool based on the image or network data you need to examine.

Best starting point for structured memory analysisVolatility and Workbench

Use Volatility capabilities through command-line or graphical workflows to examine memory artefacts.

Also consider MemProcFS for a virtual file-system view or Moneta for focused memory-threat inspection.
Explore Volatility and Workbench
05

Check analysis readiness

Record acquisition and timing context before interpreting transient evidence.

!
Preparation required5 checks remaining.