> For the complete documentation index, see [llms.txt](https://morell-tony.gitbook.io/home/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://morell-tony.gitbook.io/home/capture-the-flag/tryhackme/thm-overview/advent-of-cyber-2022/day-11-memory-forensics.md).

# \[Day 11] Memory Forensics

December 11, 2022

Today's challenge was about volatile memory forensics. Using a tool called 'volatility3' I am able to view an image of active processes in RAM. This analysis is critical in digital forensics because the volatility in this type of memory can be lost if a computer is reset or turned off.

volatility3 - <https://github.com/volatilityfoundation/volatility3>&#x20;

## Flags

### What is the Windows version number that the memory image captured?

10

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2F77MtVtm7WrdB7cHbBnZ5%2Fimage.png?alt=media\&token=69acdb86-bb85-4823-b701-35028244974b)

### What is the name of the binary/gift that secret Santa left?

mysterygift.exe

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2Fd7lv3R29Jo6blymvhf8F%2Fimage.png?alt=media\&token=ebaded18-a4fa-442d-821b-3456ff996879)

### What is the Process ID (PID) of this binary?

2040

### Dump the contents of this binary. How many files are dumped?

16

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2FGKOeLwZXVwHzVNwQOvzR%2Fimage.png?alt=media\&token=fc5ab148-db28-4e42-aab3-66b73a496ab3)
