What problem does it solve?
Manually analyzing unknown memory images during security incidents is time-intensive and risks missing subtle compromise indicators, especially when under time pressure to scope an active breach.
Core Features & Use Cases
- Standardized SANS 6-Step Workflow: Follows the industry-accepted FOR508/FOR526 memory triage methodology to ensure no critical analysis steps are missed.
- Compromise Indicator Detection: Identifies hidden processes, code injection, suspicious network activity, and unauthorized persistence mechanisms across Windows, Linux, and macOS memory images.
- Actionable Reporting: Maps all findings to MITRE ATT&CK and D3FEND frameworks to streamline incident reporting and detection backlog routing.
- Use Case: An incident responder handed an unknown memory dump from a suspected ransomware attack can use this skill to quickly surface high-priority findings like injected code or hidden persistence to guide targeted follow-up analysis.
Quick Start
Use the memory-triage skill to perform a first-pass analysis of the provided unknown memory image and generate a prioritized triage report of potential compromise indicators.