AUTOMATED RAM MEMORY FORENSIC TOOL FOR MALWARE ANALYSIS AND THREAT DETECTION
DOI:
https://doi.org/10.58885/ijcsc.v11i1.30.tynKeywords:
Memory Forensics, RAM Analysis, Malware Detection, Volatility 3, WinPMEM, YARA, Machine Learning, Deep Learning, Digital Forensics, Threat Detection.Abstract
Advanced cyber threats such as fileless malware, ransomware, and process injection attacks often reside in volatile memory, making them difficult to detect using traditional disk-based forensic techniques. This paper presents an Automated RAM Memory Forensic Tool for Malware Analysis and Threat Detection that integrates memory acquisition, forensic artifact extraction, signature-based detection, and artificial intelligence into a unified framework. The proposed system utilizes WinPmem for memory acquisition, Volatility 3 for extracting forensic artifacts, and YARA rules for identifying known malware signatures. Machine Learning and Deep Learning models are employed to detect unknown and obfuscated malware, while an ensemble decision mechanism improves detection accuracy and reduces false positives. The framework also performs automated IOC correlation, severity assessment, timeline reconstruction, and forensic report generation through a Streamlit-based interface. Experimental results demonstrate that the proposed approach improves malware detection efficiency, reduces manual investigation effort, and provides an effective solution for modern memory forensic analysis and incident response.
References
M. H. Ligh, A. Case, J. Levy, and A. Walters, The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory, Wiley, 2014.
Volatility Foundation, “Volatility 3: The volatile memory extraction framework,” official project documentation.
Volatility Foundation, “Volatility 3 Windows Tutorial,” official documentation.
Velocidex, “WinPMEM: A physical memory acquisition tool,” official project documentation.
YARA, “The pattern matching swiss army knife,” official project documentation.
S. S. H. Shah, A. R. Ahmad, N. Jamil, and A. U. R. Khan, “Memory forensics-based malware detection using computer vision and machine learning,” Electronics, vol. 11, no. 16, Art. no. 2579, 2022.
I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning, MIT Press, 2016.
T. M. Mitchell, Machine Learning, McGraw-Hill, 1997.
E. Casey, Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet, Academic Press.
N. M. N. M. A. Al-Daajeh et al., relevant literature on malware detection and digital forensics.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Authors

This work is licensed under a Creative Commons Attribution 4.0 International License.





