performing-memory-forensics-with-volatility3
mukul975/Anthropic-Cybersecurity-Skills
A comprehensive guide to analyzing volatile memory (RAM) dumps using the Volatility 3 framework. This skill enables the extraction of crucial digital evidence, including running processes, network connections, loaded modules, credentials, and encryption keys. It is essential for incident response, detecting rootkits, process hollowing, or identifying malware when traditional disk-based forensics are insufficient.