forensics@malware-lab:~/evidence$ volatility3 -f memory_dump.raw windows.pslist
[INFO] Analyzing memory dump...
[FOUND] Suspicious process: malware.exe (PID: 2847)
[FOUND] Injected code in explorer.exe (PID: 1234)
[FOUND] Hidden process: rootkit.sys (PID: 3156)
[SUCCESS] 47 processes analyzed, 3 suspicious findings
forensics@malware-lab:~/evidence$ autopsy --case infected_machine.aff
[INFO] Starting timeline analysis...
[FOUND] File system artifacts: 234 suspicious entries
[FOUND] Registry modifications: 67 malicious keys
[FOUND] Network connections: 12 C2 endpoints
[SUCCESS] Forensic analysis complete