Volatile & Network Analysis
Examine memory and network evidence to understand running processes, active connections, injected code, protocols, and communications.
Connect processes to communications
Use both evidence types where possible to test the same explanation.
Record the host, time window, addresses, users, and suspected behaviour before selecting plugins or filters.
Ask: What observable activity would support or challenge the hypothesis?Choose your evidence path
Start with the captured evidence you have, then correlate with the other source when available.
Examine running state, processes, modules, handles, and connections from a memory image.
Build your foundation
Learn what each evidence source represents before choosing analysis techniques.
Choose a tool by evidence
Select a starting tool based on the image or network data you need to examine.
Use Volatility capabilities through command-line or graphical workflows to examine memory artefacts.
Check analysis readiness
Record acquisition and timing context before interpreting transient evidence.