Showcasing Volatility 3 and its New Features by Detecting Sophisticated Malware

No ratings

Presented at BSides San Diego 2025 by

Volatility 3 is the latest version of the Volatility Memory Analysis framework, which has been the most widely used open-source framework for memory forensics since its creation in 2007. This new version of the framework is a complete rewrite starting from the first line of code. This fresh start has allowed for many brand-new features to be added that address ease of use, automation, and analyst flexibility. In this presentation, attendees will learn about all these new features while also seeing how many brand-new plugins can be used to detect a wide range of sophisticated, modern malware. This will include detection of the techniques currently deployed by ransomware and APT groups to evade EDR detection, inject code in a stealthy manner, and perform lateral movement. Examples of the techniques that will be covered include process hollowing, threadless code injection, module unhooking, and privilege escalation. Attendees will leave understanding how to detect modern malware and attacker toolkits along with slides documenting how to integrate Volatility 3 and its new features into detection workflows suitable for production use in real-world, enterprise settings.