← missions
Intermediate

Memory Forensics 101

A memory dump from a compromised workstation has been provided. Identify the malicious process, extract its network connections, and recover the C2 domain.

mission brief

450

XP reward

55 min

est. time

> Objectives

01List all running processes at time of capture
02Identify the suspicious process by name and PID
03Extract active network connections from the process
04Recover the C2 domain or IP from memory strings
#memory-forensics#malware#c2