Memory DumpAnalysis in Capture The Flag: Using Volatility 3 to Extract Hidden Files
 Repository Politeknik Negeri Batam 
Date
2024-06-12
Authors
Yusriyah, Isnaeni Hari
Arapenta, Joy Gilbert
Tambunan, Jean Tirstan
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
The field of study that examines how to uncover, collect, analyze, and present digital evidence from electronic devices is called computer forensics. This research focuses on the analysis of memory dumps in the Capture The Flag (CTF) cybersecurity competition with the aim of uncovering hidden files that may be concealed in memory by an attacker. Conducting analysis on memory dumps is an important technique in digital forensics and security incident investigation to uncover suspicious activities and hidden evidence that is not available on storage media. The Volatility Framework is utilized as the main framework for analyzing memory dumps. The analysis process adopts the general stages of the computer forensics investigation model, including acquisition, analysis, and extraction. Various Volatility plugins and modules, such as imageinfo, pslist, cmdline, filescan, grep, and dumpfiles, are optimized to identify suspicious processes, locations of hidden files, and passwords required to open encrypted files. This research shows that the Volatility Framework is an effective memory forensics tool for extracting important information from memory dumps, including hidden files, which is highly useful in the context of cybersecurity competitions such as Capture The Flag (CTF).
Description
This research analyzes memory dumps in Capture The Flag (CTF) cybersecurity competitions using computer forensics techniques. It focuses on uncovering hidden files in memory using the Volatility Framework. The methodology follows the computer forensics investigation model, including acquisition, analysis, and extraction. Various Volatility plugins are used to identify suspicious processes, locate hidden files, and find passwords for encrypted files. The results demonstrate the effectiveness of the Volatility Framework in extracting important information from memory dumps, which is valuable in the context of cybersecurity competitions like CTF.
Keywords
SOCIAL SCIENCES::Statistics, computer and systems science::Informatics, computer and systems science::Informatics, SOCIAL SCIENCES::Statistics, computer and systems science::Informatics, computer and systems science::Information technology, SOCIAL SCIENCES::Social sciences::Education
Citation
IEEE