Tech Fixx · Video
Advanced Memory Forensics with Volatility 3: Stealth Malware | Part 12
Watch this 3 min 35 sec tutorial from the Tech Fixx channel, published .
Check that the device, software and version shown match your setup. Use the player controls for captions, playback speed and full screen where available.
Loading the player connects to YouTube. If playback is unavailable here, watch on YouTube ↗.
From the video description
Part 12 moves from basic memory acquisition to advanced analysis of suspicious processes, injected code and network artifacts using Volatility 3 concepts. The goal is to form and test evidence-based hypotheses, not rely on one plugin or indicator.
You’ll learn: • Preserving and validating a memory image • Building a process and parent-child baseline • Looking for injection and process-hollowing indicators • Reviewing modules, handles and network connections • Correlating findings with disk, logs and endpoint telemetry • Recording commands, tool versions and results • Distinguishing a suspicious artifact from proof of compromise
Chapters: 0:00 The Fileless Threat 1:45 Volatile Data Preservation 4:15 Analysing Injected Threads 8:30 API Hooking & Rootkit Indicators 12:50 Reconstructing Activity 15:10 Summary & Part 13
Use only in authorised investigations or isolated training labs.
#MemoryForensics #Volatility3 #MalwareAnalysis