BSidesLuxembourg 2026

Blackhoodie training - Introduction to Linux Memory Forensics

  • 2026-05-06 , C1.03.10: lift to level 3 room #10
  • 2026-05-06 , C1.03.10: lift to level 3 room #10

All times in Europe/Luxembourg

Workshop description

What happens in memory, stays in memory! In this beginner workshop, we’ll take our first steps into the fascinating world of Linux Memory Forensics 😊.

This session will introduce the fundamentals of volatile memory, Linux memory management, with a touch on memory acquisition. We will then discover how to investigate memory artefacts and uncover traces of malicious behaviour through a simulated ransomware attack, from identifying suspicious processes and carving out binaries to recovering encryption keys from memory.

We will mostly use the Volatility framework, but this workshop will go beyond a simple command-line tutorial to explore the underlying principles: what are Volatility profiles and why do we need them, what are some interesting artefacts to look for, what to do when there is no command for what we are looking for, where do we even start looking, etc.

Who should attend?

Anyone who wants to discover digital forensics! This workshop won’t require extensive hacking knowledge, however knowing a bit about Linux will help.

Requirements

A laptop capable of running a virtual machine (or a native Linux environment), and a few gigabytes of free disk space (a memory dump can be quite heavy!). We might do a little bit of Python too! The VM will contain all the tools needed for the workshop. If you choose to use your own Linux environment instead, a setup guide will be provided.


BlackHoodie’s Mission
- BlackHoodie is a series of technical trainings aiming to attract more women to the field of cyber security
- Our events are women-only, except if individual organizers state otherwise
- Whether introduction level or advanced, classes are always challenging
- All of our events are free to attend
- We do not exert any preference in education level, occupation or corporate affiliation of attendees
- BlackHoodie is dedicated to serve the community, we aim to integrate, not separate
- BlackHoodie is independent, and cannot be leveraged to promote anything but its own mission
- We seek quality over quantity, in number of classes and attendees
- We also support/encourage attendees to start giving technical trainings thereby providing a platform to build their confidence

Sonia is a Software Engineer with a passion for Digital Forensics and CTFs