Agent skill

Memory Forensics Volatility

by yaklang in yaklang/hack-skills

Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills.

MITAuto-check passedSecurity

Install Memory Forensics Volatility

skills CLI
$ npx skills add yaklang/hack-skills --skill memory-forensics-volatility -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills memory-forensics-volatility --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/memory-forensics-volatility .claude/skills/memory-forensics-volatility && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
memory-forensics-volatility
GitHub stars
2.4k
Token cost
~2.5k tokens
SKILL.md length
376 words
Files
2
Skills in repo
26
Repo updated
First seen
Licence
MIT

At a glance

Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills.

  • Works in 7 steps: RELATED ROUTING → MEMORY ACQUISITION → VOLATILITY 2 vs 3 → …
  • Analyzing memory dumps for malware analysis
  • SKILL.md covers 0. RELATED ROUTING, 1. MEMORY ACQUISITION, 2. VOLATILITY 2 vs 3 and 3. ANALYSIS METHODOLOGY, plus 3 more sections
  • Calls make and pip3

What it does

Memory Forensics Volatility is an agent skill from yaklang/hack-skills. Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process investigation, code injection detection, and incident response timeline reconstruction.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `VOLATILITY_CHEATSHEET.md`).

It sits in Security, covering Digital forensics and Reverse engineering and malware. It works with Linux. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • Analyzing memory dumps for malware analysis
  • Credential extraction
  • Process investigation
  • Code injection detection

Example prompts

  • “/memory-forensics-volatility”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. RELATED ROUTING
  2. MEMORY ACQUISITION
  3. VOLATILITY 2 vs 3
  4. ANALYSIS METHODOLOGY
  5. LINUX MEMORY ANALYSIS
  6. MALWARE INDICATORS IN MEMORY
  7. DECISION TREE

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • pip3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip3, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Memory Forensics Volatility loads about 2.5k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 376 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 376 words, ~2,456 tokens.

Download SKILL.mdSave it as .claude/skills/memory-forensics-volatility/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
memory-forensics-volatility
description
Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process investigation, code injection detection, and incident response timeline reconstruction.

SKILL: Memory Forensics — Expert Analysis Playbook

AI LOAD INSTRUCTION: Expert memory forensics techniques using Volatility 2 and 3. Covers memory acquisition, OS identification, process analysis (hidden process detection), network connections, DLL/module analysis, code injection detection (malfind), credential extraction, file carving, registry analysis, and timeline generation. Base models miss the Vol2/Vol3 command differences, malware indicator patterns, and Linux-specific memory analysis.

Before going deep, consider loading:

Quick Reference

Also load VOLATILITY_CHEATSHEET.md when you need:

  • Vol2 vs Vol3 command comparison table
  • Common plugin sequences for specific investigation types

1. MEMORY ACQUISITION

Linux
bash
# LiME (Linux Memory Extractor) — kernel module
insmod lime.ko "path=/tmp/mem.lime format=lime"

# /proc/kcore (if available)
dd if=/proc/kcore of=/tmp/mem.raw bs=1M

# AVML (Microsoft's open-source)
./avml /tmp/mem.lime
Windows
bash
# WinPmem
winpmem_mini_x64.exe memdump.raw

# FTK Imager (GUI) — capture memory to file

# DumpIt (single-click memory dump)
DumpIt.exe

# Comae (MagnetRAM)
MagnetRAMCapture.exe /output memdump.raw
Virtual Machines
bash
# VMware: .vmem file in VM directory (suspend VM first)
# VirtualBox: VBoxManage debugvm "VM_NAME" dumpvmcore --filename mem.raw
# KVM/QEMU: virsh dump DOMAIN memdump --memory-only
# Hyper-V: checkpoint VM → inspect .bin files

2. VOLATILITY 2 vs 3

ConceptVolatility 2Volatility 3
Profile system--profile=Win10x64_19041Auto-detected (symbol tables)
Image infoimageinfowindows.info / linux.info
Process listpslistwindows.pslist
Networknetscan / connectionswindows.netscan / windows.netstat
DLLsdlllistwindows.dlllist
Injectionmalfindwindows.malfind
Hasheshashdumpwindows.hashdump
Filesfilescanwindows.filescan
Registryhivelist / printkeywindows.registry.hivelist / windows.registry.printkey
Installpip2 install volatilitypip3 install volatility3

3. ANALYSIS METHODOLOGY

Step 1: Identify OS
bash
# Vol2
vol.py -f mem.raw imageinfo
vol.py -f mem.raw kdbgscan

# Vol3
vol -f mem.raw windows.info
vol -f mem.raw banners.Banners
Step 2: Process Listing — Hidden Process Detection
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE pslist       # EPROCESS linked list
vol.py -f mem.raw --profile=PROFILE psscan       # pool tag scan (finds unlinked)
vol.py -f mem.raw --profile=PROFILE pstree       # parent-child hierarchy

# Vol3
vol -f mem.raw windows.pslist
vol -f mem.raw windows.psscan
vol -f mem.raw windows.pstree

Red flags: Process in psscan but not pslist = DKOM (Direct Kernel Object Manipulation) hiding.

Step 3: Network Connections
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE netscan      # TCP/UDP endpoints
vol.py -f mem.raw --profile=PROFILE connections   # XP/2003 only
vol.py -f mem.raw --profile=PROFILE connscan      # closed connections

# Vol3
vol -f mem.raw windows.netscan
vol -f mem.raw windows.netstat
Step 4: DLL / Module Analysis
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE dlllist -p PID
vol.py -f mem.raw --profile=PROFILE ldrmodules -p PID   # find unlinked DLLs

# Vol3
vol -f mem.raw windows.dlllist --pid PID

Red flags: DLL in dlllist but False in all three ldrmodules columns = reflective DLL injection.

Show full SKILL.md (152 more words)Show less
Step 5: Code Injection Detection (Malfind)
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE malfind -p PID
vol.py -f mem.raw --profile=PROFILE malfind -D /tmp/dump/   # dump injected sections

# Vol3
vol -f mem.raw windows.malfind --pid PID

What malfind detects: Memory regions with PAGE_EXECUTE_READWRITE that don't map to a file on disk — classic shellcode/injection indicator.

Step 6: Credential Extraction
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE hashdump      # SAM hashes
vol.py -f mem.raw --profile=PROFILE lsadump       # LSA secrets
vol.py -f mem.raw --profile=PROFILE cachedump     # domain cached creds
vol.py -f mem.raw --profile=PROFILE mimikatz      # (plugin) plaintext creds

# Vol3
vol -f mem.raw windows.hashdump
vol -f mem.raw windows.lsadump
vol -f mem.raw windows.cachedump
Step 7: File Extraction
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE filescan | grep -i "password\|secret\|flag"
vol.py -f mem.raw --profile=PROFILE dumpfiles -Q OFFSET -D /tmp/dump/

# Vol3
vol -f mem.raw windows.filescan
vol -f mem.raw windows.dumpfiles --virtaddr OFFSET
Step 8: Registry Analysis
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE hivelist
vol.py -f mem.raw --profile=PROFILE printkey -K "Software\Microsoft\Windows\CurrentVersion\Run"
vol.py -f mem.raw --profile=PROFILE userassist    # program execution evidence

# Vol3
vol -f mem.raw windows.registry.hivelist
vol -f mem.raw windows.registry.printkey --key "Software\Microsoft\Windows\CurrentVersion\Run"
Step 9: Command History
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE cmdscan       # cmd.exe history
vol.py -f mem.raw --profile=PROFILE consoles       # full console output

# Vol3
vol -f mem.raw windows.cmdline
Step 10: Timeline Generation
bash
# Vol2
vol.py -f mem.raw --profile=PROFILE timeliner --output=body --output-file=timeline.body
mactime -b timeline.body -d > timeline.csv

# Vol3
vol -f mem.raw timeliner.Timeliner

4. LINUX MEMORY ANALYSIS

bash
# Vol2 (requires Linux profile)
vol.py -f mem.lime --profile=LinuxProfile linux_pslist
vol.py -f mem.lime --profile=LinuxProfile linux_pstree
vol.py -f mem.lime --profile=LinuxProfile linux_netstat
vol.py -f mem.lime --profile=LinuxProfile linux_bash        # bash history
vol.py -f mem.lime --profile=LinuxProfile linux_enumerate_files
vol.py -f mem.lime --profile=LinuxProfile linux_proc_maps -p PID
vol.py -f mem.lime --profile=LinuxProfile linux_malfind

# Vol3
vol -f mem.lime linux.pslist
vol -f mem.lime linux.pstree
vol -f mem.lime linux.bash
vol -f mem.lime linux.check_afinfo     # rootkit detection
vol -f mem.lime linux.check_syscall    # syscall hooking
vol -f mem.lime linux.tty_check        # TTY hooking
Building Linux Profiles (Vol2)
bash
cd volatility/tools/linux
make
# Creates module.dwarf + System.map → zip as profile
zip LinuxProfile.zip module.dwarf /boot/System.map-$(uname -r)
# Place in volatility/plugins/overlays/linux/

5. MALWARE INDICATORS IN MEMORY

IndicatorDetection MethodWhat It Means
Process in psscan but not pslistCompare pslist vs psscanDKOM — process hiding
Unexpected parent-childpstree analysise.g., svchost spawned by cmd.exe
MZ header in non-image memorymalfindReflective DLL / PE injection
RWX memory without backing filemalfindShellcode injection
DLL unlinked from all PEB listsldrmodules (all False)Stealth DLL loading
svchost.exe not child of services.exepstreeFake svchost (malware)
Unusual network connectionsnetscan + PID correlationC2 communication
Hooking in SSDT/IDTssdt / idt pluginsRootkit
Modified kernel objectslinux_check_syscallLinux rootkit
Normal Parent-Child Relationships (Windows)
System (4)
└── smss.exe
    └── csrss.exe
    └── wininit.exe
        └── services.exe
            └── svchost.exe (multiple)
            └── spoolsv.exe
        └── lsass.exe
    └── winlogon.exe
        └── explorer.exe
            └── user applications

6. DECISION TREE

Memory dump acquired — need to analyze
│
├── What OS?
│   ├── Windows → vol imageinfo / windows.info (§3 Step 1)
│   └── Linux → build profile or use Vol3 auto-detect (§4)
│
├── Malware investigation?
│   ├── Check processes: pslist vs psscan (hidden?) (§3 Step 2)
│   ├── Check parent-child: pstree (suspicious spawning?) (§5)
│   ├── Check injections: malfind (RWX memory?) (§3 Step 5)
│   ├── Check DLLs: ldrmodules (unlinked?) (§3 Step 4)
│   ├── Check network: netscan (C2 connections?) (§3 Step 3)
│   └── Extract suspicious files: dumpfiles (§3 Step 7)
│
├── Credential recovery?
│   ├── SAM hashes → hashdump (§3 Step 6)
│   ├── LSA secrets → lsadump (§3 Step 6)
│   ├── Cached domain creds → cachedump (§3 Step 6)
│   └── Plaintext passwords → mimikatz plugin (§3 Step 6)
│
├── Incident timeline?
│   ├── timeliner for comprehensive timeline (§3 Step 10)
│   ├── cmdscan / consoles for command history (§3 Step 9)
│   ├── userassist for program execution (§3 Step 8)
│   └── Cross-reference with PCAP timeline (→ traffic-analysis-pcap)
│
├── CTF / flag hunting?
│   ├── filescan + grep for flag patterns (§3 Step 7)
│   ├── cmdscan for typed flags/passwords (§3 Step 9)
│   ├── Clipboard: clipboard plugin
│   ├── Screenshots: screenshot plugin
│   └── Environment vars: envars plugin
│
└── Linux-specific?
    ├── linux_bash for shell history (§4)
    ├── linux_check_syscall for rootkit (§4)
    └── linux_netstat for connections (§4)

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/memory-forensics-volatility of yaklang/hack-skills.

  • SKILL.md
  • VOLATILITY_CHEATSHEET.md

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

Memory Forensics Volatility next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Memory Forensics Volatility compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Memory Forensics Volatility this skillyaklang/hack-skills2.4k—~2.5kAutomated safety check: PassMIT
Runtime Memory Sample Acquisitiondslsdzc/rev-skills117—~2kAutomated safety check: PassApache-2.0
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Forensics OsqueryAgentSecOps/SecOpsAgentKit2191 repos~4.9kAutomated safety check: NotesCustom licence
Analyzing Memory Forensics With Lime And Volatilitymukul975/Anthropic-Cybersecurity-Skills34k—~631Automated safety check: PassApache-2.0
Performing Memory Forensics With Volatility3 Pluginsmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    117 GitHub stars~2k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    219 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Analyzing Memory Forensics With Lime And Volatility

    mukul975/Anthropic-Cybersecurity-Skills

    Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework.

    34k GitHub stars~631 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Memory Forensics With Volatility3 Plugins

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Memory Dumps With Volatility

    mukul975/Anthropic-Cybersecurity-Skills

    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from yaklang/hack-skills

All 26 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 24 days ago
    Auto-check passed
  • API Auth And JWT Abuse

    yaklang/hack-skills

    API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~567 tokensUpdated 24 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 24 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 24 days ago
    Auto-check passed
  • Attack Surface Mapping

    yaklang/hack-skills

    Draw a testable attack surface from one authorized target URL or one application.

    2.4k GitHub stars~2.6k tokensUpdated 24 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 24 days ago
    Auto-check passed

Works with

Categories

Questions about Memory Forensics Volatility

What does Memory Forensics Volatility do?

Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills. Memory Forensics Volatility is an agent skill from yaklang/hack-skills. Memory forensics playbook using Volatility 2/3.

When should I use Memory Forensics Volatility?

Memory Forensics Volatility fits situations like: analyzing memory dumps for malware analysis; credential extraction; process investigation; code injection detection.

How do I install Memory Forensics Volatility in Claude Code?

Run `npx skills add yaklang/hack-skills --skill memory-forensics-volatility -a claude-code`. Or copy the skill folder (skills/memory-forensics-volatility in yaklang/hack-skills) into .claude/skills/memory-forensics-volatility in your project. Claude Code loads it when a task matches its description.

How do I install Memory Forensics Volatility in Codex?

Run `npx skills add yaklang/hack-skills --skill memory-forensics-volatility -a codex`. Or copy the skill folder (skills/memory-forensics-volatility in yaklang/hack-skills) into .agents/skills/memory-forensics-volatility in your project. Codex loads it when a task matches its description.

Can I use Memory Forensics Volatility in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill memory-forensics-volatility -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/memory-forensics-volatility, .gemini/skills/memory-forensics-volatility, .github/skills/memory-forensics-volatility and .opencode/skills/memory-forensics-volatility in your project.

What does Memory Forensics Volatility need to run?

Going by SKILL.md and its folder, Memory Forensics Volatility needs the command-line tools its instructions call (make and pip3). Our summary lists: Python 3.

Does Memory Forensics Volatility access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Memory Forensics Volatility safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Memory Forensics Volatility use?

Memory Forensics Volatility is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Memory Forensics Volatility use?

About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Memory Forensics Volatility?

Skills that share tags, products or a category with Memory Forensics Volatility: Runtime Memory Sample Acquisition (dslsdzc/rev-skills, 117 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Forensics Osquery (AgentSecOps/SecOpsAgentKit, 219 stars) and Analyzing Memory Forensics With Lime And Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Memory Forensics Volatility?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,381 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.