Recover the truth hidden in memory.

You have been provided with a Windows memory image from a compromised system.

Your objective is to reconstruct the suspicious process, identify the relevant memory region, recover its runtime configuration, and determine the complete execution chain.

EVIDENCE DarkMatter.raw
Q1 SYSTEM IDENTIFICATION

Identify the Windows operating system, architecture, and build.

Q2 SUSPICIOUS PROCESS

Identify the suspicious process and its PID.

Q3 PROCESS PARENT

Identify the parent process of the suspicious process and its PID.

Q4 VIRTUAL ADDRESS DESCRIPTOR

Identify the suspicious VAD by providing its start address, end address, protection, VAD type, and size.

Q5 MEMORY SIGNIFICANCE

Explain why the suspicious VAD is significant to the investigation.

Q6 VAD EXTRACTION

Provide the dumped VAD filename and its SHA-256 hash.

Q7 RUNTIME CONFIGURATION

Recover the primary runtime configuration and identify the decoy configuration.

Q8 PE / STATIC ANALYSIS

Identify the executable architecture, PE format, and relevant memory-management APIs.

Q9 MEMORY COMPARISON

Compare the executable-backed memory with the private runtime memory. Which contains the cleaner configuration and why?

Q10 EXECUTION CHAIN

Reconstruct the relevant process execution chain from the memory image.

Once you have verified your answers, submit the complete investigation.