• GitHub
  • Contact
The Volatility Foundation - Promoting Accessible Memory Analysis Tools Within the Memory Forensics Community
  • The Volatility Framework
  • Training
  • Events
  • FAQ
  • Contest
  • About
  • Blog
Select Page

MoVP 2.1 Atoms (The New Mutex), Classes and DLL Injection

by Volatility | Sep 17, 2012 | forensics, kernel, malware, movp, volatility, windows

Month of Volatility Plugins In this post, we will discuss various ways you can analyze malware and understand infections by analyzing the atom tables. You’ll be surprised that creating window classes, registering window messages, injecting DLLs with message...

MoVP 1.5 KBeast Rootkit, Detecting Hidden Modules, and sysfs

by Volatility | Sep 14, 2012 | forensics, kernel, linux, malware, movp, volatility

Month of Volatility Plugins In this post I will analyze the KBeast rootkit using Volatility’s new Linux features.  This will include finding hidden modules, network connections, opened files, and hooked system calls. If you would like to follow along or recreate...

MoVP 1.4 Average Coder Rootkit, Bash History, and Elevated Processes

by Volatility | Sep 13, 2012 | forensics, kernel, linux, malware, movp, volatility

Month of Volatility Plugins In this post I will begin showcasing some of Volatility’s new Linux features by analyzing a popular Linux kernel rootkit named “Average Coder”.  These new features will include recovering .bash_history from memory, finding userland...

MoVP 1.3 Desktops, Heaps, and Ransomware

by Volatility | Sep 12, 2012 | forensics, kernel, malware, movp, volatility, windows

Month of Volatility Plugins  The MoVP 1.3 plugin, named deskscan, enumerates desktops, desktop heap allocations, and associated threads. In the GUI landscape, a desktop is essentially a container for application windows and user interface objects. Malware...

MoVP 1.2 Window Stations and Clipboard Malware

by Volatility | Sep 11, 2012 | forensics, kernel, malware, movp, volatility, windows

Month of Volatility Plugins  We previously discussed sessions, which are containers for processes and other objects related to a user’s logon session. Among those other objects are window stations, which act as security boundaries for processes and...
« Older Entries
Next Entries »

Volatility Blog Archive

2026

  • + March (1)

2025

  • + July (1)
  • + May (2)
  • + March (1)

2024

  • + August (1)
  • + July (1)
  • + March (1)

2023

  • + August (1)
  • + July (1)
  • + June (1)
  • + March (1)
  • + February (1)
  • + January (1)

2022

  • + July (1)
  • + February (1)
  • + January (1)

2021

  • + October (1)
  • + August (1)
  • + May (1)
  • + January (1)

2020

  • + November (1)
  • + May (2)

2019

  • + November (1)
  • + October (2)
  • + July (1)
  • + June (1)

2018

  • + November (2)
  • + May (1)
  • + February (1)

2017

  • + November (1)
  • + June (1)
  • + April (1)

2016

  • + December (2)
  • + September (1)
  • + August (2)
  • + July (1)
  • + April (3)

2015

  • + November (2)
  • + October (1)
  • + August (2)
  • + July (2)
  • + June (1)
  • + May (1)
  • + March (1)
  • + February (1)
  • + January (1)

2014

  • + December (1)
  • + October (3)
  • + September (5)
  • + August (6)
  • + July (2)
  • + May (1)
  • + April (2)
  • + February (2)
  • + January (5)

2013

  • + October (3)
  • + September (2)
  • + August (1)
  • + June (9)
  • + May (15)
  • + April (2)
  • + March (2)
  • + February (1)
  • + January (4)

2012

  • + December (2)
  • + November (1)
  • + October (14)
  • + September (19)
bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    Loading Comments...

    You must be logged in to post a comment.