RAM Triage - paste the Volatility output, get the memory-forensics verdict
Paste the output of your Volatility 3 plugin runs (pslist, psscan, cmdline, netscan, malfind) and get an incident-response triage report: suspicious processes each with a verbatim evidence quote from your own paste, injected memory assessed against its page protection, network indicators, persistence, an IOC table with CSV export, a timeline, containment steps, and the exact follow-up Volatility commands for the PIDs it flagged. A free client-side parser rebuilds the process tree in your browser and flags unlinked processes, masquerading system binaries, RWX regions, encoded command lines and anti-recovery commands before you run anything - then audits the report against those facts and shows any disagreement. A derived work of the open-source @wshobson/memory-forensics agent skill (MIT).
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.