#memory-forensics
Security firm Trail of Bits has released mquire, a Linux memory forensics tool that works without any external dependencies

blog.trailofbits.com/2026/02/25/m...
mquire: Linux memory forensics without external dependencies
We’re open-sourcing mquire, a tool that analyzes Linux memory dumps without requiring any external debug information.
blog.trailofbits.com
February 28, 2026 at 5:57 PM
Our talk from @defcon.bsky.social is now available! In the presented research, we document every EDR bypass technique used in the wild along with how to detect it using new memory forensics techniques and Volatility plugins. Feedback appreciated!

www.youtube.com/watch?v=Pmqv...
DEF CON 32 - Defeating EDR Evading Malware with Memory Forensics - Case, Sellers, Richard, et al.
YouTube video by DEFCONConference
www.youtube.com
October 23, 2024 at 3:20 PM
Our highly popular and technical training, "Malware and Memory Forensics with Volatility", has been fully converted to @volatilityfoundation.org 3 and significantly updated, including many new sections and 8 new, in-depth labs. Available online & in VA in October

memoryanalysis.net/courses-malw...
Malware and Memory Forensics Training - Memory Analysis
Malware and memory forensics training courses offered by the Memory Analysis Team.
memoryanalysis.net
June 11, 2025 at 4:36 PM
The next in-person offering of our Malware and Memory Forensics Training will be held in Arlington, VA from Oct 21st-24th. This course has converted to Volatility 3, and all the material and labs are updated to cover the latest threats & analysis techniques

memoryanalysis.net/courses-malw...
Malware and Memory Forensics Training - Memory Analysis
Malware and memory forensics training courses offered by the Memory Analysis Team.
memoryanalysis.net
September 3, 2025 at 5:11 PM
MemProcFS is a GREAT Memory Forensics tool. Sharing here in case you have not checked this before! #DFIR #MemoryForensics #MemProcFS

github.com/ufrisk/MemPr...
GitHub - ufrisk/MemProcFS: MemProcFS
MemProcFS. Contribute to ufrisk/MemProcFS development by creating an account on GitHub.
github.com
November 14, 2024 at 11:32 PM
Want to learn reverse engineering? There'll be a free, women*-only BlackHoodie workshop from October 6th to 9th in Paris!

Topics:
• Linux memory forensics 🕵️‍♀️ (by Sonia)
• Web app and mobile app pentesting 🕸️📱 (by Paula)
• iOS reversing 🍎 (by me)
September 10, 2025 at 7:52 PM
November 17, 2024 at 9:17 PM
hurts_just_a_little_bit.jpg
December 3, 2024 at 2:20 AM
Dive Into Malware Forensics: A Walkthrough of REMnux, The Redux
Dive Into Malware Forensics: A Walkthrough of REMnux, The Redux
Dive Into Malware Forensics: A Walkthrough of REMnux, The Redux For cyber-defenders, threat hunters, and malware analysts, moving from static code analysis to live memory forensics is where abstract …
infosecwriteups.com
July 5, 2026 at 7:09 AM
Check out the back of my new favorite @volexity.bsky.social shirt that I acquired at FTSCon! Using memory forensics to find 0days in network appliances and high value applications will never get old!
November 10, 2024 at 5:04 PM
You probably want more than a factory reset to be sure it's forensics-clean in light of wear leveling in flash memory controllers
Reminder: Never travel out of the country with your main cell phone (or without backing it up and then doing a factory reset) or laptop.

CBP agents are effectively Redcoats and they WILL delight in reminding you that they owe you no rights.
October 7, 2025 at 9:46 PM
Roey Shua will be speaking at our Volexity Cyber Sessions in Amsterdam (Oct 29) about automating edge device forensics, from fingerprinting unknown routers & IoT devices to reconstructing symbols and acquiring memory on unsupported architectures.

Seating is limited! Register here: luma.com/0qtkw49c
September 22, 2026 at 2:21 PM
Congratulations to all of the Volatility contributors - this was no small feat! We are proud to be a sustaining sponsor of this important open-source project that remains the world’s most widely used memory forensics platform. #dfir
We are very excited to announce that Volatility 3 has reached parity with Volatility 2! With this achievement, Volatility 2 is now deprecated. See the full details in our blog post: volatilityfoundation.org/announcing-t...
Announcing the Official Parity Release of Volatility 3!
Visit the post for more.
volatilityfoundation.org
May 16, 2025 at 3:20 PM
Digital Forensics StartMe Page by Dillon Bowe

- SANS posters & cheatsheets
- Blog feed
- YouTube feed
- Memory tools
- Network tools
- Malware tools
- getting started guides

and more.

start.me/p/1kRlPp/for...

#dfir
April 28, 2025 at 1:18 PM
CHIMERA sounds incredible! Identity and forensics is such a great combo. Fellow psych thriller author here. My debut SHE REMEMBERS EVERYTHING explores memory and murder. amazon.com/dp/B0FCD1TMZJ
April 2, 2026 at 2:18 AM
Experimenting with @warp.dev for memory forensics, and the results are fascinating and impressive. Its not replacing an analyst anytime soon, but it can certainly help with initial triage.

#dfir
March 6, 2025 at 2:10 PM
We are excited to announce FTSCon 2025 on October 20, 2025, in Arlington VA! Registration is now OPEN + we have a Call for Speakers.

Following FTSCon will be a 4-day Malware & Memory Forensics Training course with Volatility 3.

See the full details here: volatilityfoundation.org/announcing-f...
Announcing FTSCon 2025 & In-person Malware and Memory Forensics Training!
Mark your calendars for Monday, October 20, 2025! We will again be hosting FTSCon in Arlington, Virginia.You can read more event details here. Registration is now open!
volatilityfoundation.org
May 23, 2025 at 6:00 PM
This is my first post on here. For those who don’t know me, I’ve been involved with the Volatility Framework since around 2007 (https://www.volatilityfoundation.org/). I’ve worked DFIR for over 15 years, and conduct various trainings in DFIR for private companies, as well as public venues
The Volatility Foundation - Open Source Memory Forensics
The Volatility Foundation is an independent 501(c) (3) non-profit organization that maintains and promotes The Volatility memory forensics framework.
www.volatilityfoundation.org
June 27, 2023 at 11:05 AM
What a fantastic time at #SARMAC2025 in Kildare, Ireland! So great connecting with researchers in #memory + #cognition, learning about topics in #ageing, #forensics + #law!

My research talk explored my @officialsarmac.bsky.social funded #PhD work on #multilingualism + #cognitiveageing 🧠 🌱
June 13, 2025 at 5:02 PM
One of the grossest things in recent memory was when Philly media uncovered that UPenn and Princeton had the bones of children killed in the 1985 Move police bombing and used them as props in an online forensics class whyy.org/articles/mov...
October 10, 2024 at 1:05 PM
Malware Analysis Tools

Mindmap of links:

Encoding/Decoding tools
File Carving tools
Memory Forensics
Online scanners
Malware analysis tools
Debuggers/Decompliers

malwareanalysis.tools
December 23, 2023 at 5:21 PM
🐧 **mquire – Linux memory forensics and analysis tool**

mquire is a Linux memory forensics and analysis tool for querying kernel memory dumps using SQL. The post mquire – Linux memory forensics and analysis tool appeared first on LinuxLinks.

📰 Source: LinuxLinks
🔗 Link […]
Original post on igeek.gamer-geek-news.com
igeek.gamer-geek-news.com
June 11, 2026 at 4:06 AM
You are right, remember signal is encrypted therefore is Not history or memory after deleted.. signal can’t used forensics to get back historical records AKA text!
March 26, 2025 at 11:48 PM