Capture memory before you lose it
Task
Put something in memory that exists nowhere on disk, then demonstrate the order of volatility by capturing it — and by losing it. This is why 'do not power off' is the first instruction a first responder is given.
Steps
- Write
/tmp/holder.py: a script that reads the markerLABMARKERfrom a file, holds it in a variable, deletes the source file, and then sleeps. Run it in the background and note its PID. Keep the marker off the disk everywhere else, or step 2 finds it: not in holder.py's own source, and not typed whole at a prompt that saves history -- create the file withprintf 'LAB%s' MARKER > /tmp/secret.txt. - Confirm the marker is genuinely not on disk any more: search the filesystem for it and find nothing.
- Now capture the process memory:
sudo gcore <pid>, or read/proc/<pid>/mapsand dump the writable regions. - Search the capture for the marker and find it. This is evidence that exists in exactly one place.
- Record the order of volatility in
/tmp/volatility.md, from registers down to archival media, and mark where your marker sat. - Now destroy it the way a well-meaning responder does: kill the process, or reboot the VM. Search again and confirm the evidence is unrecoverable.
Files the Verify reads
The Verify block reads these by name, so save them exactly here:
-
/tmp/core.*-- the memory capture from step 3 --sudo gcore -o /tmp/core <pid>writes/tmp/core.<pid>.
Verify
sudo grep -rc "LABMARKER" / --exclude-dir=proc --exclude-dir=sys --exclude-dir=dev --exclude-dir=run --exclude='core.*' 2>/dev/null | awk -F: '{s+=$2} END {print s+0" on-disk occurrence(s)"}'
grep -c "LABMARKER" /tmp/core.* 2>/dev/null
python3 - <<'PY'
import glob
cores=glob.glob('/tmp/core.*')
assert cores, 'no memory capture was taken'
found=any(b'LABMARKER' in open(c,'rb').read() for c in cores)
print('marker recovered from memory capture:',found)
assert found, 'the marker was not in the capture - check the process was still running'
PY
grep -ciE "registers|\bram\b|disk|archival" /tmp/volatility.md
The first must be 0 — the marker is nowhere on disk. It names directories by base name (proc, not /proc: grep matches --exclude-dir against the name, so /proc would exclude nothing and grep would find the marker in its own command line under /proc/self), and it skips the capture file, which is on disk by design. The assertion must find it in the memory capture. That pair is the demonstration: a piece of evidence that exists only in RAM, and that a reboot removes permanently.
Notes
Fileless malware, injected code, attacker shell sessions and decryption keys all live exactly where your marker did. Pulling the plug on a compromised machine destroys all of it, which is why the instruction is to isolate the host from the network and capture memory while it is still running.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.