← All CDFI Flashcard Decks

Memory Forensics & Volatile Data Analysis Flashcards

7 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Memory Forensics & Volatile Data Analysis flashcards as text
  1. What is the EPROCESS structure in Windows memory forensics?

    Answer: The kernel executive process object containing all metadata about a running process

    EPROCESS is the Windows kernel's executive process object, containing fields such as PID, PPID, image name, token, handle table, and linked-list pointers.

  2. What is Direct Kernel Object Manipulation (DKOM) and why is it forensically significant?

    Answer: A rootkit technique that modifies kernel data structures to hide malicious processes or objects

    DKOM allows rootkits to hide processes by unlinking EPROCESS entries from the active process list, making them invisible to tools that walk the linked list.

  3. Which Volatility plugin best detects processes hidden by DKOM by scanning raw memory pool tags rather than walking linked lists?

    Answer: psscan

    `psscan` scans physical memory for EPROCESS pool tags directly, finding processes that DKOM has unlinked from the active process list.

  4. What is the purpose of analyzing the Virtual Address Descriptor (VAD) tree in Windows memory forensics?

    Answer: To map the virtual memory layout of a process and identify suspicious injected code regions

    The VAD tree describes all virtual memory regions allocated within a process, and anomalous regions with RWX permissions and no backing file often indicate code injection.

  5. Which type of artifact found in memory forensics is generally NOT recoverable through disk-based forensic analysis?

    Answer: Plaintext contents of encrypted volumes that are actively mounted

    Encrypted volume contents are decrypted in RAM while the container is mounted, so memory forensics is the only way to capture plaintext data from active encrypted volumes.

  6. What can examining Master File Table (MFT) entries cached in memory reveal that may not be available through disk analysis alone?

    Answer: File access patterns and recently accessed files providing additional timeline context

    MFT entries cached in memory may capture access timestamps and file activity not yet flushed to disk, enriching the forensic timeline.

  7. During memory analysis, a process has a Parent Process ID (PPID) pointing to a non-existent process. What does this most likely indicate?

    Answer: A potential DKOM attack or a process spawned by malware that subsequently terminated to avoid detection

    An orphaned PPID is a strong indicator that malware spawned a child process and then terminated itself, or that DKOM was used to manipulate process-parent relationships.