Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Power of 2
@pwr2@infosec.exchange  ·  activity timestamp 3 days ago

Update:

Our velociraptor plugin `Windows.Memory.Mem2Disk` can detect RAM injections and fileless malware.

We tested it against (among others) the C2 frameworks Sliver, Havoc and Mythic. All three were detected.

It was recently featured in a blog post by Mike Cohen:

https://docs.velociraptor.app/blog/2025/2025-11-15-memory-analysis-pt1

Stay tuned for memory analysis with velo part 2!

#C2 #detection #memoryforensics #velociraptor #DFIR #cybersecurity #infosec #pwr2

Memory Analysis with Velociraptor - Part 1 :: Velociraptor - Digging deeper!

This Blog post explores Velociraptor's memory analysis capabilities.
  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login