Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
Need to capture network connections, running processes, and system state
Legal proceedings may require forensic evidence preservation
Incident requires root cause analysis with volatile data
Detection Gaps & Validation
Order of volatility is non-negotiable (RFC 3227): registers/cache → RAM → network state → running processes → disk → archival. Capturing netstat/tasklistbefore the memory image is the classic mistake — every command you run allocates memory and overwrites freed pages, smearing the very RAM you need for fileless malware. Image memory FIRST, then collect live state.
RAM smear / page inconsistency: acquisition is not atomic, so the kernel keeps running and structures shift mid-dump (process lists vs. actual). Acquire as fast as possible, record start/end timestamps, and treat single-pass dumps of a live host as inherently slightly inconsistent — corroborate findings (a netscan connection) against a second source (Zeek/firewall).
Don't trust the host's own binaries: a rootkit hooks ps, netstat, ls, and lsof to hide itself. Run only the trusted toolkit from external media, and compare host-reported processes/ports against the memory image — a connection in RAM that netstat omits is a strong rootkit signal.
Encryption/anti-forensics: BitLocker/LUKS volumes are readable while mounted but lost on power-off; memory holds the keys. This is why isolate-and-image beats pull-the-plug unless the host is actively destroying data.
Validation: hash every artifact immediately (sha256sum) and re-verify against the manifest before transfer; confirm the memory image is parseable (load it in Volatility and list processes) before leaving the scene; and reconcile volatile findings across at least two independent sources to rule out tool-level deception.
Prerequisites
Forensic collection toolkit on USB or network share (trusted tools)
WinPmem/LiME for memory acquisition
Write-blocker or forensic workstation for disk imaging
Chain of custody documentation forms
Secure evidence storage with integrity verification
Authorization to collect evidence (legal/HR approval for insider cases)
Workflow
Step 1: Prepare Collection Environment
# Mount forensic USB toolkit (do NOT install tools on compromised system)# Verify toolkit integritysha256sum /mnt/forensic_usb/tools/* > /tmp/toolkit_hashes.txt
diff /mnt/forensic_usb/tools/known_good_hashes.txt /tmp/toolkit_hashes.txt
# Create evidence output directory with timestamps
EVIDENCE_DIR="/mnt/evidence/$(hostname)_$(date +%Y%m%d_%H%M%S)"mkdir -p "$EVIDENCE_DIR"echo"Collection started: $(date -u)" > "$EVIDENCE_DIR/collection_log.txt"echo"Collector: $(whoami)" >> "$EVIDENCE_DIR/collection_log.txt"echo"System: $(hostname)" >> "$EVIDENCE_DIR/collection_log.txt"
Step 2: Capture System Memory (Highest Volatility)
# Windows - WinPmem memory acquisition
winpmem_mini_x64.exe "$EVIDENCE_DIR\memdump_$(hostname).raw"# Linux - LiME kernel module for memory acquisition
insmod /mnt/forensic_usb/lime.ko "path=$EVIDENCE_DIR/memdump_$(hostname).lime format=lime"# Linux - Alternative using /proc/kcoreddif=/proc/kcore of="$EVIDENCE_DIR/kcore_dump.raw" bs=1M
# macOS - osxpmem
osxpmem -o "$EVIDENCE_DIR/memdump_$(hostname).aff4"# Hash the memory dump immediatelysha256sum"$EVIDENCE_DIR/memdump_"* > "$EVIDENCE_DIR/memory_hash.sha256"
Step 3: Capture Network State
# Active network connections# Windows
netstat -anob > "$EVIDENCE_DIR/netstat_connections.txt" 2>&1
Get-NetTCPConnection | Export-Csv "$EVIDENCE_DIR/tcp_connections.csv" -NoTypeInformation
Get-NetUDPEndpoint | Export-Csv "$EVIDENCE_DIR/udp_endpoints.csv" -NoTypeInformation
# Linux
ss -tulnp > "$EVIDENCE_DIR/socket_stats.txt"
netstat -anp > "$EVIDENCE_DIR/netstat_all.txt" 2>/dev/null
cat /proc/net/tcp > "$EVIDENCE_DIR/proc_net_tcp.txt"cat /proc/net/udp > "$EVIDENCE_DIR/proc_net_udp.txt"# ARP cache
arp -a > "$EVIDENCE_DIR/arp_cache.txt"# Routing table
route print > "$EVIDENCE_DIR/routing_table.txt"# Windows
ip route show > "$EVIDENCE_DIR/routing_table.txt"# Linux# DNS cache
ipconfig /displaydns > "$EVIDENCE_DIR/dns_cache.txt"# Windows# Linux: varies by resolver, check systemd-resolve or nscd
systemd-resolve --statistics > "$EVIDENCE_DIR/dns_stats.txt" 2>/dev/null
# Active firewall rules
netsh advfirewall show allprofiles > "$EVIDENCE_DIR/firewall_rules.txt"# Windows
iptables -L -n -v > "$EVIDENCE_DIR/iptables_rules.txt"# Linux
Step 4: Capture Running Processes
# Windows - Detailed process list
tasklist /V /FO CSV > "$EVIDENCE_DIR/process_list_verbose.csv"
wmic process list full > "$EVIDENCE_DIR/wmic_process_full.txt"
Get-Process | Select-Object Id,ProcessName,Path,StartTime,CPU,WorkingSet |
Export-Csv "$EVIDENCE_DIR/ps_processes.csv" -NoTypeInformation
# Windows - Process with command line and parent
wmic process get ProcessId,Name,CommandLine,ParentProcessId,ExecutablePath /FORMAT:CSV > \
"$EVIDENCE_DIR/process_commandlines.csv"# Linux - Full process tree
ps auxwwf > "$EVIDENCE_DIR/process_tree.txt"
ps -eo pid,ppid,user,args --forest > "$EVIDENCE_DIR/process_forest.txt"cat /proc/*/cmdline 2>/dev/null | tr'\0'' ' > "$EVIDENCE_DIR/proc_cmdline_all.txt"# Process modules/DLLs loaded# Windows
listdlls.exe -accepteula > "$EVIDENCE_DIR/loaded_dlls.txt"# Linuxfor pid in $(ls /proc/ | grep -E '^[0-9]+$'); doecho"=== PID $pid ===" >> "$EVIDENCE_DIR/proc_maps.txt"cat"/proc/$pid/maps" 2>/dev/null >> "$EVIDENCE_DIR/proc_maps.txt"done# Open file handles
handle.exe -accepteula > "$EVIDENCE_DIR/open_handles.txt"# Windows (Sysinternals)
lsof > "$EVIDENCE_DIR/open_files.txt"# Linux
Step 5: Capture Logged-in Users and Sessions
# Windows
query user > "$EVIDENCE_DIR/logged_in_users.txt"
query session > "$EVIDENCE_DIR/active_sessions.txt"
net session > "$EVIDENCE_DIR/net_sessions.txt" 2>&1
net use > "$EVIDENCE_DIR/mapped_drives.txt" 2>&1
# Linuxwho > "$EVIDENCE_DIR/who_output.txt"
w > "$EVIDENCE_DIR/w_output.txt"
last -50 > "$EVIDENCE_DIR/last_logins.txt"
lastlog > "$EVIDENCE_DIR/lastlog.txt"cat /var/log/auth.log | tail -200 > "$EVIDENCE_DIR/recent_auth.txt" 2>/dev/null