| name | performing-endpoint-forensics-investigation |
| description | Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.
|
| domain | cybersecurity |
| subdomain | endpoint-security |
| tags | ["endpoint","forensics","memory-analysis","disk-imaging","incident-investigation","Volatility"] |
| version | 1.0.0 |
| author | mahipal |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","PR.PS-02","DE.CM-01","PR.IR-01"] |
| mitre_attack | ["T1055","T1547","T1059","T1036","T1005"] |
Performing Endpoint Forensics Investigation
When to Use
Use this skill when:
- Investigating a confirmed or suspected endpoint compromise requiring forensic analysis
- Collecting volatile and non-volatile evidence for incident response or legal proceedings
- Analyzing memory dumps for malware, injected code, or credential theft artifacts
- Reconstructing attacker timelines from endpoint artifacts (prefetch, shimcache, amcache)
Do not use this skill for live threat hunting (use EDR/SIEM) or network forensics.
Prerequisites
- Forensic workstation with analysis tools (Volatility 3, KAPE, Autopsy, Eric Zimmerman tools)
- Write-blocker for disk imaging (hardware or software)
- Secure evidence storage with chain-of-custody documentation
- Memory acquisition tool (WinPMEM, FTK Imager, Magnet RAM Capture)
- Administrative access to the target endpoint (or physical access)
Workflow
Step 1: Evidence Preservation (Order of Volatility)
Collect evidence from most volatile to least volatile:
1. System memory (RAM) - Most volatile
2. Network connections and routing tables
3. Running processes and open files
4. Disk contents (file system)
5. Removable media
6. Logs and backup data - Least volatile
Memory Acquisition:
# WinPMEM (Windows)
winpmem_mini_x64.exe memdump.raw
# FTK Imager - Create memory capture via GUI
# File → Capture Memory → Destination path → Capture Memory
# Linux (LiME kernel module)
sudo insmod lime.ko "path=/evidence/memory.lime format=lime"
Volatile Data Collection:
# Capture running processes
Get-Process | Export-Csv "evidence\processes.csv" -NoTypeInformation
tasklist /v > "evidence\tasklist.txt"
# Capture network connections
netstat -anob > "evidence\netstat.txt"
Get-NetTCPConnection | Export-Csv "evidence\tcp_connections.csv"
# Capture logged-on users
query user > "evidence\logged_users.txt"
# Capture scheduled tasks
schtasks /query /fo CSV /v > "evidence\scheduled_tasks.csv"
# Capture services
Get-Service | Export-Csv "evidence\services.csv"
# Capture DNS cache
ipconfig /displaydns > "evidence\dns_cache.txt"
Step 2: Disk Imaging
# FTK Imager - Create forensic disk image
# File → Create Disk Image → Physical Drive → E01 format
# Always verify image hash (MD5/SHA1) matches source
# dd (Linux)
sudo dc3dd if=/dev/sda of=/evidence/disk.dd hash=sha256 log=/evidence/imaging.log
# Verify image integrity
sha256sum /evidence/disk.dd
# Compare with hash generated during imaging