Skip to main content

I tested what Windows RAM actually preserves after normal user activity

0
Medium
Published: 09/13/2026 (09/13/2026, 21:56:36 UTC)
Source: Reddit ExploitDev

Description

This report details a controlled memory forensics investigation on a Windows 11 system to determine what user activity can be reconstructed from a RAM capture. The experiment involved normal user actions such as browsing with Edge, running PowerShell commands, and typing unsaved text in Notepad. Memory was acquired using WinPmem and analyzed with Volatility 3, revealing recoverable artifacts including running processes, command-line arguments, network state, and unsaved text. The findings emphasize that memory forensics is most effective when multiple artifacts are correlated rather than analyzed in isolation. This is a research and educational exercise rather than a vulnerability or exploit.

Reddit Discussion

r/ExploitDev·posted by u/chronosAndCode
00

I wanted to see how much normal Windows activity could actually be reconstructed from a RAM capture, so I built a small controlled Windows 11 lab.

Before acquisition I intentionally:

opened Edge and browsed to a website

launched PowerShell

ran whoami, ipconfig, and Get-Process

opened Notepad

typed unsaved text and left it open

I captured memory with WinPmem, hashed the image with SHA-256, and analyzed it in Kali with Volatility 3.

The most useful findings were:

msedge.exe, powershell.exe, Notepad.exe, and explorer.exe recovered from memory

parent/child relationships showing PowerShell and Notepad launched from explorer.exe

command-line paths for the processes

execution-related strings for whoami.exe and ipconfig.exe

references to Get-Process

network state associated with Edge using windows.netstat

the exact unsaved Notepad text recovered directly from RAM

One thing I found interesting was that windows.netscan returned nothing useful, while windows.netstat did recover network state. It was a good reminder not to rely on one plugin as the only source of truth.

The biggest takeaway for me was that the investigation became useful only when the artifacts were correlated rather than treated separately.

I wrote up the full lab with screenshots and commands here:

https://chronosandcode.com/memory-forensics-investigation-volatility/

Disclosure: this is my own write-up on Chronos & Code. All activity was generated inside a lab I controlled.

I’d be curious what other Volatility plugins people here would have used on the same image.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 13:47:10 UTC

Technical Analysis

A security researcher created a controlled Windows 11 lab environment to test what information remains in RAM after typical user activity. Using WinPmem, a raw memory image was captured while Edge, PowerShell, and Notepad were active. Analysis with Volatility 3 on a separate Kali Linux system recovered detailed artifacts such as process lists, parent-child relationships, command-line arguments, network connections, and unsaved user text. The investigation demonstrated that RAM contains rich forensic evidence beyond disk artifacts, but effective analysis requires correlating multiple data points. This work serves as a practical demonstration of memory forensics capabilities and limitations, with no indication of a new vulnerability or exploit.

Potential Impact

There is no direct security impact or vulnerability described. The report illustrates that RAM captures can reveal detailed system and user activity artifacts, which is valuable for forensic investigations. It highlights the potential for memory analysis to recover sensitive information such as unsaved text and command history if an attacker or investigator obtains a memory image. However, this is a known characteristic of RAM and not a newly discovered security flaw.

Defensive Guidance

This is an educational memory forensics exercise with no associated vulnerability or exploit requiring remediation. No patch or fix is applicable. Organizations should continue to protect memory acquisition vectors and ensure proper authorization and legal authority for forensic investigations. No urgent mitigation actions are needed based on this report.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ExploitDev+pwned+hacking
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":32,"reasons":["external_link","established_author"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa94c5955bf5e2cf5e42610

Added to database: 09/15/2026, 13:47:05 UTC

Last enriched: 09/15/2026, 13:47:10 UTC

Last updated: 09/16/2026, 03:31:29 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses