🧠 Live Memory Forensics Lab — Mandiant Redline (Full Workflow)🎯 Lab ObjectivePerform a real-world memory forensic investigation on an infected Windows VM using Mandiant Redline, covering:Infection → Data Collection → Transfer → Analysis → IOC Identification🧪 Lab OverviewEnvironment:
Target: Windows 7 Virtual Machine (infected)
Malware Sample: her.exe (Dyre/Dridex family behavior)
Tool: Mandiant Redline
⚠️ Critical Rule❌ NEVER analyze forensic data on the infected machine ✅ ALWAYS transfer to a clean analysis system🔧 Part 1: Operational Reality & Troubleshooting💣 Step 1: Execute Malware (Inside VM Only)
Run her.exe
Allow infection to occur
Observe system behavior (optional monitoring)
📥 Step 2: Run Redline Collector
Perform memory audit
Output size: ~9 GB
🚧 Problem: Data Transfer FailureLarge forensic data often:
Fails to copy
Gets interrupted
Exceeds VM limitations
🛠️ Troubleshooting Techniques1. Network ReconfigurationSwitch VM network mode:
From: Host-Only
To: NAT (Network Address Translation)
✔ Enables outbound communication ✔ Allows file transfer2. Smart Data ReductionInstead of copying full audit:
Locate Sessions Folder
Copy ONLY:
Sessions/ directory
🔥 Why This Works
Sessions folder contains analysis-ready data
Avoids transferring unnecessary bulk files
🧠 Key InsightReal DFIR work includes solving infrastructure problems — not just analysis🔍 Part 2: Deep-Dive Forensic Investigation🧾 Step 1: Load Data into Redline
Open Sessions folder
Begin analysis on clean machine
📊 Investigation Areas1. 🖥️ System InformationCollect:
Operating System
IP Address
MAC Address
RAM Size
Logged-in Users
🎯 Purpose:
Establish investigation baseline
Required for incident reporting
2. 🌐 Listening PortsAnalyze:
Active ports
Open sockets
External connections
🚨 Look for:
Unknown ports
Suspicious outbound traffic
Mapping to malicious processes
💡 Example:
Malware (ELC / ELIC) tied to network activity
3. 🔤 Strings & Memory ArtifactsExtract:
Command-line activity
File paths
Embedded indicators
🎯 Goal:
Identify what executed in memory
Reveal hidden behavior
4. 🗃️ Registry PersistenceTechnique:
Sort registry keys by:
Last Modified Time
🚨 Look for:
Recent suspicious changes
Auto-start entries
Persistence mechanisms
🔥 Key Insight:Attackers modify registry to survive reboot5. 🌳 Process Hierarchy (CRITICAL)Analyze process tree:Track execution flow:her.exe → spawns → ech.exe → further activity 🚨 Look for:
Parent-child relationships
Hidden or injected processes
Unusual process chains
💡 Example Behavior:
her.exe (initial payload)
spawns hidden process ech.exe
6. 🧬 Indicators of Compromise (IOCs)Use:
Known malicious hashes
Threat intel feeds
Redline Capabilities:
Auto-flag suspicious artifacts
Search across memory dataset
🎯 Goal:
Confirm malicious presence
Identify scope of compromise
🧠 Investigation MindsetYou are answering:
What executed?
What changed?
What communicated externally?
How did it persist?
⚠️ Key Challenges Highlighted
Large data handling (GB-scale)
VM networking issues
Data transfer limitations
Environment troubleshooting
🧠 Key Takeaways
Memory analysis is data-heavy and complex
Operational issues are part of real DFIR work
Process trees reveal true attack flow
Registry analysis exposes persistence
Network artifacts expose exfiltration
🚨 Golden DFIR WorkflowInfect → Capture → Isolate → Transfer → Analyze → Correlate → Report📌 Pro Tips (Real-World)