HomeCybersecurityLinux Memory Forensics: Volatility-Style Process Analysis

Linux Memory Forensics

Interactive memory-forensics simulator: scan a Linux RAM dump, list running processes, uncover a rootkit-hidden process, extract network connections and recover unflushed bash history — modeled on Volatility-style pslist vs. pool-scan analysis.

Cybersecurity3DAdvanced60 FPS
linux-memory-forensics-volatility-style-process-analysis ↗ Open standalone

A 3D memory-forensics simulator: scan a captured RAM dump, list running processes, and compare a linked-list process walk against a raw pool scan to uncover a rootkit-hidden process, its C2 network connection and its attacker's unflushed bash history.

⚙ Under the hood

Scan a captured Linux RAM dump in 3D and compare a ps-style linked-list process walk against a Volatility-style pool scan to uncover a rootkit-hidden process, its C2 network connection and unflushed bash history recovered straight from process memory.

Three.jsCybersecurityDigital ForensicsMemory ForensicsLinuxVolatility

3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)