Analyzed memory dumps for anomalous processes, persistence, and network indicators; mapped findings to MITRE ATT&CK and documented repeatable investigation evidence.
Project details
- Memory investigation
Analyzes memory dumps as part of digital-forensics investigations.
- Process analysis
Examines anomalous processes for evidence of suspicious activity.
- Persistence checks
Investigates persistence indicators within the available evidence.
- Network indicators
Reviews network indicators to connect system activity with potential threats.
- Technique mapping
Maps investigation findings to MITRE ATT&CK techniques.
- Repeatable evidence
Documents investigation evidence and repeatable steps using Volatility, Wireshark, and MITRE ATT&CK.