Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Windows Memory & User Activity

Premium room

Trace user behavior, command execution, file access, and macro-based payload delivery from memory.

medium

60 min

2,270

User profile photo.

To access material, start machines and answer questions login.

In this room, we’ll walk through how to investigate user activity from a Windows memory dump using Volatility 3. As analysts, it's important to know what users were doing on a system at the time something suspicious occurred. That includes knowing who was logged in, what commands were executed, and what files were opened, among other activities.

This room is the second in a set of three. We’ll be working with a memory dump from a compromised machine on a small internal network. If the host is indeed compromised, we will need to piece together the scope of the attack and the attack chain.

Learning Objectives

  • Link logins to suspicious activity using session and registry data.
  • Identify commands and file access tied to suspicious access.
  • Reconstruct user actions from memory.

Prerequisites

Answer the questions below

Click to continue to the room.