Verdict
A plain-language answer first: compromised or not, and which process to look at.
In-browser memory forensics
Open a RAM dump from Windows or Linux and explore it as a machine, not a pile of plugin tables: the programs that were running and who started them, what they were talking to, what they had open, who was logged in, what was typed — with the suspicious parts flagged and explained. Nothing is uploaded.
Your RAM dump never leaves this device. Parsing runs in WebAssembly on a Web Worker — nothing is uploaded.
RAM is not a file on disk: capture it from the running machine with one command, or pick up a memory file that Windows or the hypervisor already wrote. Easiest routes first.
Needs: an administrator Command Prompt (cmd.exe, not PowerShell) and a USB drive mounted as E: that holds winpmem_mini_x64_rc2.exe and has more free space than the machine has RAM. Change E: if your drive has another letter.
E:\winpmem_mini_x64_rc2.exe E:\%COMPUTERNAME%.rawWrites E:\<computer name>.raw, a raw image that loads directly.
Needs: root, and the AVML static binary (made executable) on external storage mounted at /mnt/usb.
sudo /mnt/usb/avml /mnt/usb/$(hostname).limeWrites /mnt/usb/<hostname>.lime in LiME format (AVML's default), which loads directly.
Magnet RAM Capture (free): run it as administrator, choose the USB drive as the destination, click Start. It writes a raw image.
Magnet RAM Capture guide →Suspend the VM, or snapshot it with memory, and drop its .vmem. Nothing runs inside the guest. Paths are under “VMs & disk images”.
Task Manager → Details → right-click System → Create live kernel memory dump file → Full live kernel memory dump. Kernel memory only, no user-mode process memory. Saved under %LocalAppData%\Microsoft\Windows\TaskManager\LiveKernelDumps.
Needs: an administrator prompt in the folder that holds the Velociraptor binary, renamed velociraptor.exe; E: is the external drive.
velociraptor.exe artifacts collect Windows.Memory.Acquisition --output E:\memory.zipThe memory image ends up inside the ZIP: extract the raw image and drop that file (ZIPs are not opened). If the artifact offers a compression option, leave it off.
Needs: root, in the folder that holds the Velociraptor binary, renamed velociraptor; /mnt/usb is external storage.
sudo ./velociraptor artifacts collect Linux.Memory.Acquisition --output /mnt/usb/memory.zipSame as on Windows: extract the memory image from the ZIP, then drop it here.
Needs: an administrator prompt in the KAPE folder; E: is the external drive.
kape.exe --tsource C: --tdest E:\kape --target MemoryFilesThe MemoryFiles target copies pagefile.sys, hiberfil.sys and swapfile.sys into E:\kape. That is not a RAM image: attach pagefile.sys after loading a Windows dump (“+ pagefile” button); hiberfil.sys must be converted first.
File → Capture Memory…: choose the USB drive as the destination, keep the memdump.mem name and leave “Create AD1 file” unchecked. Tick “Include pagefile” to also get pagefile.sys, which you can attach after loading the dump.
Suspend the VM, or take a snapshot that includes memory, so the hypervisor writes the .vmem. Drop the .vmem; the .vmss / .vmsn next to it is only the state descriptor.
%USERPROFILE%\Documents\Virtual Machines\<VM>\*.vmem~/Virtual Machines.localized/<VM>.vmwarevm/*.vmem/vmfs/volumes/<datastore>/<VM>/*.vmemVBoxManage debugvm "<VM>" dumpvmcore --filename vm.elfMount the image (Arsenal Image Mounter, or FTK Imager → Image Mounting) or add it as evidence in FTK Imager, then export these files from the root of the Windows volume. This only gives you what Windows wrote before it went down, not a live capture.
\Windows\MEMORY.DMP\hiberfil.sys\pagefile.sysMemory files Windows writes on its own. hiberfil.sys, pagefile.sys and swapfile.sys are hidden system files, locked while Windows runs: take them from a mounted image or copy them with KAPE or FTK Imager. Drop one file at a time.
%SystemRoot%\MEMORY.DMP%LocalAppData%\Microsoft\Windows\TaskManager\LiveKernelDumps%SystemDrive%\hiberfil.sys%SystemDrive%\pagefile.sys%SystemDrive%\swapfile.sysAccepted formats: raw images (.raw, .mem, .bin, .vmem), LiME, AVML (uncompressed or --compress) and x64 Windows crash dumps (MEMORY.DMP full or bitmap, DumpIt .dmp). Hibernation files, AFF4, ELF cores and QCOW2 must be converted to raw first. The OS (Windows, Linux, macOS) is detected from content, not the extension.
Each view is a window on one part of the machine; detections are drawn on top of it, never instead of it.
A plain-language answer first: compromised or not, and which process to look at.
Every program on a lifespan timeline with its lineage, memory map, loaded code, open files and rights.
Process starts, connections, registry writes, file times and log lines on one zoomable axis.
Who talked to whom, what the machine exposed, and when each connection was opened.
Accounts, who held dangerous rights, and the password hashes, keys and credentials left in memory.
Commands typed or executed, scheduled jobs, logins and logs recovered from memory.
Windows 7 – 11, x64. Kernel symbols are fetched from Microsoft automatically; every view is available.
x86-64 kernels with a matching Volatility 3 symbol file (found automatically for common distributions, or upload your own).
Detected; analysis is limited to text-pattern plugins for now.
The tool rebuilds the machine from kernel structures — processes, memory, sockets, handles, accounts — and only then flags what is abnormal, with the reason in plain words.
The Rust parser runs on Web Workers in your browser. Multi-gigabyte images stay responsive; there is nothing to install.
The image is read locally and never uploaded — suitable for sensitive incident-response evidence.
It stays on your machine the whole time.
The kernel is identified and its symbols fetched (Microsoft for Windows, the Volatility 3 community index for Linux).
Start at the verdict, then follow the links into processes, network, accounts and activity.
No. Parsing runs entirely client-side in WebAssembly on a Web Worker — the file never leaves your device.
Windows 7 through 11 and Linux get the full, structured analysis (kernel symbols are fetched automatically). macOS images are detected, with limited pattern-based analysis for now.
No. RAM parser runs in any modern browser — there is nothing to install, no Python environment and no symbol packs to manage.
Raw physical memory dumps such as .raw, .mem, .dmp and .lime, captured with tools like Magnet RAM Capture, WinPmem or AVML.
The parser streams pages on demand instead of loading the whole file, so multi-gigabyte images work without exhausting browser memory.
Yes — RAM parser is free to use directly in your browser.