How CAPEv2's Memory Forensics Module Functions: Volatility 3 Integration and Capabilities
TLDR: CAPEv2's memory forensics module automates memory dump analysis using Volatility 3, orchestrating plugin execution through the Memory class in modules/processing/memory.py to extract artifacts, detect tainted processes, and generate JSON reports.
The CAPEv2 memory forensics module provides deep inspection of sandbox memory dumps by integrating the Volatility 3 framework directly into the processing pipeline. Located in modules/processing/memory.py, this component executes automatically when memory dumps are available, enriching analysis reports with forensic artifacts such as process listings, injected code detection, and extracted strings.
Architectural Overview
CAPEv2 implements memory forensics as a standard processing module. When an analysis generates a memory dump (stored at memory_path), the Memory class validates the environment and instantiates VolatilityManager to handle the forensic workflow. This architecture decouples the CAPEv2 reporting structure from Volatility 3's internal context management while preserving full access to the framework's plugin ecosystem.
The module operates through a coordinated sequence: initialization of the Volatility 3 context, selective plugin execution based on configuration, JSON serialization of results, and post-processing for threat intelligence extraction.
Core Components and Source Implementation
The Memory Processing Class
The Memory class serves as the entry point for memory analysis within CAPEv2's processing framework. According to the source code in modules/processing/memory.py, the Memory.run() method verifies that Volatility 3 is available and that the memory dump file exists before delegating execution to VolatilityManager.
# Conceptual flow based on CAPEv2 source structure
class Memory(Processing):
def run(self):
# Verify volatility3 availability and dump existence
# Instantiate VolatilityManager and execute analysis
manager = VolatilityManager(self.memory_path)
return manager.run()
VolatilityManager Orchestration
VolatilityManager coordinates the entire forensic analysis lifecycle. Its __init__ method reads the memory configuration section to determine which plugins to enable, while the run() method iterates through the plugin map and executes each enabled analysis module.
As implemented in modules/processing/memory.py, this manager handles:
- Plugin selection from the static
plugins_mapdictionary - Execution via
VolatilityAPI - Post-processing through
find_taint(),do_strings(), andcleanup()
VolatilityAPI Wrapper
The VolatilityAPI class provides a thin abstraction over Volatility 3's library interface. The run() method creates a fresh Volatility 3 Context, loads automagics for automatic layer and symbol detection, constructs the requested plugin with optional PID filtering, and executes the plugin.
# Simplified representation of the VolatilityAPI workflow
class VolatilityAPI:
def run(self, plugin_name, pids=None):
context = Context()
# Load automagics and construct plugin
plugin = construct_plugin(context, plugin_name, pids)
# Execute and return JSON via ReturnJsonRenderer
return render_output(plugin.run())
Custom JSON Rendering
To integrate Volatility 3's output with CAPEv2's JSON-based reporting, the module implements ReturnJsonRenderer. This subclass converts Volatility's native TreeGrid output format into plain Python dictionaries suitable for serialization, storing results under plugin-specific keys in the final analysis report.
Plugin Configuration and Execution
The module uses a static plugins_map dictionary in modules/processing/memory.py that maps friendly names (e.g., pslist, malfind, yarascan) to fully-qualified Volatility 3 plugin class paths. Only plugins whose corresponding entries are enabled in the configuration are executed.
Configuration resides in conf/default/memory.conf.default, where each plugin has its own section:
[pslist]
enabled = true
[malfind]
enabled = true
[basic]
delete_memdump = false
dostrings = true
strings_minchars = 5
strings_nullterminated_only = true
Advanced Capabilities
Automated Taint Detection
The find_taint() function analyzes malfind plugin results to identify processes containing injected code or unmapped memory sections. Detected Process IDs (PIDs) are flagged as "tainted" and recorded in the analysis metadata, enabling correlation with other CAPEv2 behavioral indicators.
This taint information allows the sandbox to mark specific processes as suspicious for downstream signature matching and behavioral correlation.
String Extraction
When basic.dostrings is enabled, the do_strings() function performs regex-based string extraction directly from the raw memory dump. The module writes extracted strings to a companion <dump>.strings file, respecting configuration parameters for minimum character length and null-termination requirements.
Automated Cleanup
The cleanup() function provides storage management by optionally deleting memory dumps and accompanying ZIP archives after processing. Controlled by the basic.delete_memdump setting, this feature prevents disk space exhaustion in high-volume environments while preserving forensic data when needed for manual review.
Practical Implementation Examples
Accessing Memory Analysis Results
Once analysis completes, memory forensics data is available in the JSON report under the memory key:
import requests
def get_memory_forensics(task_id):
response = requests.get(f"http://localhost:8000/tasks/view/{task_id}/json")
analysis = response.json()
memory_data = analysis.get("memory", {})
# Extract process list from pslist plugin
processes = memory_data.get("pslist", [])
for proc in processes:
print(f"PID {proc['PID']}: {proc['ImageFileName']}")
# Check for tainted processes
if memory_data.get("taint"):
print(f"Tainted PIDs detected: {memory_data['taint']}")
return memory_data
Configuring Plugin Selection
To optimize analysis speed, disable resource-intensive plugins in conf/default/memory.conf.default:
[malfind]
enabled = false
[vadinfo]
enabled = false
[pslist]
enabled = true
After modifying the configuration, restart CAPEv2 processing workers to apply changes. The next analysis will skip disabled plugins while retaining core functionality.
Summary
- CAPEv2's memory forensics module integrates Volatility 3 through
modules/processing/memory.py, providing automated analysis of sandbox memory dumps. - Core architecture includes the
Memoryentry point,VolatilityManagerorchestration, andVolatilityAPIwrapper for plugin execution. - Configurable plugin system uses a static
plugins_mapandconf/default/memory.conf.defaultto select which Volatility 3 plugins run during analysis. - Advanced features include taint detection via
find_taint(), string extraction throughdo_strings(), and automated cleanup withcleanup(). - JSON serialization is handled by
ReturnJsonRenderer, converting Volatility'sTreeGridoutput into CAPEv2-compatible report structures.
Frequently Asked Questions
How does CAPEv2's memory forensics module integrate with Volatility 3?
The module acts as a wrapper around Volatility 3, utilizing the VolatilityAPI class to create a fresh Volatility context, load automagics, and execute plugins programmatically. Results are captured via a custom ReturnJsonRenderer that converts Volatility's native output into JSON format suitable for CAPEv2 reports, all orchestrated through the VolatilityManager class in modules/processing/memory.py.
What Volatility 3 plugins are available in CAPEv2's memory forensics module?
The module supports a configurable set of plugins defined in the plugins_map dictionary within modules/processing/memory.py, including pslist (process listing), malfind (injected code detection), yarascan (YARA rule matching), and various other forensic plugins. Administrators enable specific plugins by setting enabled = true in the corresponding sections of conf/default/memory.conf.default.
How does taint detection work in CAPEv2 memory analysis?
The find_taint() function processes results from the malfind plugin to identify processes containing suspicious memory allocations or injected code. These Process IDs are marked as "tainted" in the analysis report, allowing CAPEv2 to correlate memory-based indicators with behavioral analysis data and flag potentially malicious activity for further investigation.
Can I extract strings from memory dumps in CAPEv2?
Yes, enable the basic.dostrings option in conf/default/memory.conf.default to activate the do_strings() function. This feature reads the raw memory dump file, applies configurable regex patterns based on strings_minchars and strings_nullterminated_only settings, and outputs findings to a <dump>.strings file alongside the primary analysis results.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →