| name | collecting-volatile-evidence-from-compromised-host |
| description | Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost. Use when working with collecting volatile evidence from compromised host. |
| domain | cybersecurity |
| tags | ["incident-response","dfir","forensics","volatile-evidence","memory-forensics","chain-of-custody"] |
| subdomain | incident-response |
| mitre_attack | ["T1003","T1055","T1059","T1547"] |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["RS.MA-01","RS.MA-02","RS.AN-03","RC.RP-01"] |
Collecting Volatile Evidence From Compromised Host
Overview
Cybersecurity skill for collecting volatile evidence from compromised host. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"collecting volatile evidence from compromised host"
-
"Collect volatile forensic evidence from a compromised system following order of "
-
Security incident confirmed and compromised host identified
-
Before system isolation, shutdown, or remediation begins
-
Memory-resident malware suspected (fileless attacks)
-
Need to capture network connections, running processes, and system state
-
Legal proceedings may require forensic evidence preservation
-
Incident requires root cause analysis with volatile data
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Forensic collection toolkit on USB or network share (trusted tools)
- WinPmem/LiME for memory acquisition
- Write-blocker or forensic workstation for disk imaging
- Chain of custody documentation forms
- Secure evidence storage with integrity verification
- Authorization to collect evidence (legal/HR approval for insider cases)
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}