memory-forensics
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.
npx skills add sickn33/agentic-awesome-skills --skill memory-forensics --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# Memory Forensics Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis. ## Use this skill when - Working on memory forensics tasks or workflows - Needing guidance, best practices, or checklists for memory forensics ## Do not use this skill when - The task is unrelated to memory forensics - You need a different domain or tool outside this scope ## Instructions - Clarify goals, constraints, and required inputs. - Apply relevant best practices and validate outcomes. - Provide actionable steps and verification. - If detailed examples are required, open `resources/implementation-playbook.md`. ## Memory Acquisition ### Live Acquisition Tools #### Windows ```powershell # WinPmem (Recommended) winpmem_mini_x64.exe memory.raw # DumpIt DumpIt.exe # Belkasoft RAM Capturer # GUI-based, outputs raw format # Magnet RAM Capture # GUI-based, outputs raw format ``` #### Linux ```bash # LiME (Linux Memory Extractor) sudo insmod lime.ko "path=/tmp/memory.lime format=lime" # /dev/mem (limited, requires permissions) sudo dd if=/dev/mem of=memory.raw bs=1M # /proc/kcore (ELF format) sudo cp /proc/kcore memory.elf ``` ##
- Use this skill when
- Do not use this skill when
- Instructions
- Memory Acquisition
- Live Acquisition Tools
- Virtual Machine Memory
- Volatility 3 Framework
- Installation and Setup
- Essential Plugins
- Linux Analysis
- macOS Analysis
- Analysis Workflows
- Malware Analysis Workflow
- Incident Response Workflow
LiME (Linux Memory Extractor) sudo insmod lime.ko "path=/tmp/memory.lime format=lime" sudo dd if=/dev/mem of=memory.raw bs=1M sudo cp /proc/kcore memory.elf osxpmem sudo ./osxpmem -o memory.raw MacQuisition (commercial) cp vm.vmem memory.raw vboxmanage debugvm "VMName" dumpvmcore --filename memory.elf QEMU
What does the memory-forensics skill do?
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.
How do I install it?
Run `npx skills add sickn33/agentic-awesome-skills --skill memory-forensics --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From sickn33/agentic-awesome-skills, a repository with 44,414 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.