Skip to content
Nullcon Goa

Modern Memory Forensics for Linux & Windows


Course

Rajesh Kumar Natarajan and Srinivasan Govindarajan present a framework that combines Volatility 3 and RAG to simplify memory forensics, enrich artifacts with threat intelligence and generate accurate insights for faster detection of advanced threats.

Memory forensics is essential for investigating advanced threats like fileless malware and kernel-level rootkits, yet analyzing raw memory remains complex and resource-intensive. This session introduces a scalable framework that integrates Volatility 3 with Retrieval-Augmented Generation to simplify and accelerate memory analysis across Linux and Windows systems while minimizing LLM hallucinations.

 

In this session, you will gain insights into:

  • Leveraging Volatility 3 to extract and structure critical memory artifacts such as processes, memory regions and network activity;
  • Enriching artifacts with threat intelligence, behavioral context and real-world IOCs from controlled malware analysis;
  • Using a RAG-powered pipeline to enable accurate, context-aware insights without retraining models, improving efficiency in threat detection and investigation. 

Here is the course outline:

Volatility Meets AI: Transforming Linux and Windows Memory Forensics for Modern Threats

Completion

The following certificates are awarded when the course is completed:

CPE Credit Certificate

Floating Button