In-browser memory forensics

See what the machine was doing when its memory was captured

Open a RAM dump from Windows or Linux and explore it as a machine, not a pile of plugin tables: the programs that were running and who started them, what they were talking to, what they had open, who was logged in, what was typed — with the suspicious parts flagged and explained. Nothing is uploaded.

Your RAM dump never leaves this device. Parsing runs in WebAssembly on a Web Worker — nothing is uploaded.

No image yet? How to get one

How to get a memory image

RAM is not a file on disk: capture it from the running machine with one command, or pick up a memory file that Windows or the hypervisor already wrote. Easiest routes first.

  1. CollectOne command on the live machine, as admin or root.
  2. Drop the file hereOne .raw, .mem, .vmem, .lime or .dmp file, not zipped.
  3. It stays in your browserParsed locally in WebAssembly: nothing is uploaded.

Windows: WinPmem

recommended

Needs: an administrator Command Prompt (cmd.exe, not PowerShell) and a USB drive mounted as E: that holds winpmem_mini_x64_rc2.exe and has more free space than the machine has RAM. Change E: if your drive has another letter.

E:\winpmem_mini_x64_rc2.exe E:\%COMPUTERNAME%.raw

Writes E:\<computer name>.raw, a raw image that loads directly.

Linux: AVML

recommended

Needs: root, and the AVML static binary (made executable) on external storage mounted at /mnt/usb.

sudo /mnt/usb/avml /mnt/usb/$(hostname).lime

Writes /mnt/usb/<hostname>.lime in LiME format (AVML's default), which loads directly.

No command line?

Magnet RAM Capture (free): run it as administrator, choose the USB drive as the destination, click Start. It writes a raw image.

Magnet RAM Capture guide →

Virtual machine?

Suspend the VM, or snapshot it with memory, and drop its .vmem. Nothing runs inside the guest. Paths are under “VMs & disk images”.

Windows 11, nothing to download

Task Manager → Details → right-click System → Create live kernel memory dump file → Full live kernel memory dump. Kernel memory only, no user-mode process memory. Saved under %LocalAppData%\Microsoft\Windows\TaskManager\LiveKernelDumps.

Gotchas

  • Capture first and do not reboot or shut down: RAM is gone at power-off, and every tool you run on the host overwrites some of it.
  • Write to an external or network drive with more free space than the installed RAM, never to the suspect's own disk. Admin or root is required, and Secure Boot or an EDR can block the capture driver.
  • One uncompressed file per analysis: extract it from any ZIP first. Hibernation files, AFF4, ELF cores and QCOW2 must be converted to raw.

What you get

Each view is a window on one part of the machine; detections are drawn on top of it, never instead of it.

Verdict

A plain-language answer first: compromised or not, and which process to look at.

Processes

Every program on a lifespan timeline with its lineage, memory map, loaded code, open files and rights.

Timeline

Process starts, connections, registry writes, file times and log lines on one zoomable axis.

Network

Who talked to whom, what the machine exposed, and when each connection was opened.

Accounts & secrets

Accounts, who held dangerous rights, and the password hashes, keys and credentials left in memory.

Activity

Commands typed or executed, scheduled jobs, logins and logs recovered from memory.

Operating systems

Windows

structured

Windows 7 – 11, x64. Kernel symbols are fetched from Microsoft automatically; every view is available.

Linux

structured

x86-64 kernels with a matching Volatility 3 symbol file (found automatically for common distributions, or upload your own).

macOS

partial

Detected; analysis is limited to text-pattern plugins for now.

Why RAM parser

  • A window, then the verdict

    The tool rebuilds the machine from kernel structures — processes, memory, sockets, handles, accounts — and only then flags what is abnormal, with the reason in plain words.

  • Runs in WebAssembly

    The Rust parser runs on Web Workers in your browser. Multi-gigabyte images stay responsive; there is nothing to install.

  • Nothing leaves your device

    The image is read locally and never uploaded — suitable for sensitive incident-response evidence.

How it works

  1. 1

    Drop a memory image

    It stays on your machine the whole time.

  2. 2

    Symbols load automatically

    The kernel is identified and its symbols fetched (Microsoft for Windows, the Volatility 3 community index for Linux).

  3. 3

    Investigate

    Start at the verdict, then follow the links into processes, network, accounts and activity.

Related tools

Frequently asked questions

+ Is my RAM dump uploaded anywhere?

No. Parsing runs entirely client-side in WebAssembly on a Web Worker — the file never leaves your device.

+ Which operating systems are supported?

Windows 7 through 11 and Linux get the full, structured analysis (kernel symbols are fetched automatically). macOS images are detected, with limited pattern-based analysis for now.

+ Do I need to install Volatility or any other tools?

No. RAM parser runs in any modern browser — there is nothing to install, no Python environment and no symbol packs to manage.

+ What file formats can I open?

Raw physical memory dumps such as .raw, .mem, .dmp and .lime, captured with tools like Magnet RAM Capture, WinPmem or AVML.

+ How large a dump can it handle?

The parser streams pages on demand instead of loading the whole file, so multi-gigabyte images work without exhausting browser memory.

+ Is RAM parser free?

Yes — RAM parser is free to use directly in your browser.