AUTOMATED RAM MEMORY FORENSIC TOOL FOR MALWARE ANALYSIS AND THREAT DETECTION

Authors

  • Tejavath Yogeswar Naik Department of Computer Science and Engineering, University College of Engineering Science and Technology, Jawaharla Nehru Technological University, Kukatpally, Hyderabad, Telangana, India
  • KP Supreethi Department of Computer Science and Engineering, University College of Engineering Science and Technology, Jawaharla Nehru Technological University, Kukatpally, Hyderabad, Telangana, India

DOI:

https://doi.org/10.58885/ijcsc.v11i1.30.tyn

Keywords:

Memory Forensics, RAM Analysis, Malware Detection, Volatility 3, WinPMEM, YARA, Machine Learning, Deep Learning, Digital Forensics, Threat Detection.

Abstract

Advanced cyber threats such as fileless malware, ransomware, and process injection attacks often reside in volatile memory, making them difficult to detect using traditional disk-based forensic techniques. This paper presents an Automated RAM Memory Forensic Tool for Malware Analysis and Threat Detection that integrates memory acquisition, forensic artifact extraction, signature-based detection, and artificial intelligence into a unified framework. The proposed system utilizes WinPmem for memory acquisition, Volatility 3 for extracting forensic artifacts, and YARA rules for identifying known malware signatures. Machine Learning and Deep Learning models are employed to detect unknown and obfuscated malware, while an ensemble decision mechanism improves detection accuracy and reduces false positives. The framework also performs automated IOC correlation, severity assessment, timeline reconstruction, and forensic report generation through a Streamlit-based interface. Experimental results demonstrate that the proposed approach improves malware detection efficiency, reduces manual investigation effort, and provides an effective solution for modern memory forensic analysis and incident response.

References

M. H. Ligh, A. Case, J. Levy, and A. Walters, The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory, Wiley, 2014.

Volatility Foundation, “Volatility 3: The volatile memory extraction framework,” official project documentation.

Volatility Foundation, “Volatility 3 Windows Tutorial,” official documentation.

Velocidex, “WinPMEM: A physical memory acquisition tool,” official project documentation.

YARA, “The pattern matching swiss army knife,” official project documentation.

S. S. H. Shah, A. R. Ahmad, N. Jamil, and A. U. R. Khan, “Memory forensics-based malware detection using computer vision and machine learning,” Electronics, vol. 11, no. 16, Art. no. 2579, 2022.

I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning, MIT Press, 2016.

T. M. Mitchell, Machine Learning, McGraw-Hill, 1997.

E. Casey, Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet, Academic Press.

N. M. N. M. A. Al-Daajeh et al., relevant literature on malware detection and digital forensics.

Downloads

Published

2026-09-27

How to Cite

Tejavath Yogeswar Naik, & KP Supreethi. (2026). AUTOMATED RAM MEMORY FORENSIC TOOL FOR MALWARE ANALYSIS AND THREAT DETECTION. International Journal of Computer Science & Communications (IJCSC), 11(1), 30–41. https://doi.org/10.58885/ijcsc.v11i1.30.tyn

Issue

Section

ORIGINAL RESEARCH