Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

In a memory forensics investigation using Volatility, an analyst wants to see a list of processes that were active at the time of acquisition, including hidden processes. Which Volatility command should be used?

⚠ Common exam trap

Many exam-takers confuse pslist (which lists only linked processes) with psscan (which finds hidden processes), mistakenly believing pslist can detect all active processes because it is the most commonly used command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

psscan

Psscan, because it scans the physical memory for _EPROCESS structures, allowing it to detect processes that are hidden from the standard linked list used by pslist. This makes psscan the appropriate command for identifying hidden or unlinked processes that were active at the time of acquisition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pslist

    Why it's wrong here

    pslist walks the kernel's doubly-linked list of EPROCESS objects starting from PsActiveProcessHead. Because it relies on this active list, any process that a rootkit unlinks to hide itself will simply not appear in the output. It also doesn't scan memory for orphaned structures, making it ineffective against common direct kernel object manipulation (DKOM) attacks.

  • ✗

    pstree

    Why it's wrong here

    pstree builds a parent-child hierarchy by traversing the same PsActiveProcessHead linked list used by pslist, so it inherits exactly the same blind spot for unlinked processes. While it adds valuable relationship information, it cannot expose hidden or detached EPROCESS objects that are no longer reachable from the list head. Thus it is just as vulnerable as pslist to hidden-process evasion.

  • ✗

    netscan

    Why it's wrong here

    netscan is a network artifact plugin that enumerates TCP/UDP connections and listening sockets by scanning for network-related pool structures, not processes. It tells you that some process has a connection, but it does not provide a complete, authoritative list of running processes. Even if a process has no network activity, it would be absent from netscan output, so it cannot answer the question 'what processes are running?'

  • ✓

    psscan

    Why this is correct

    psscan bypasses the linked list entirely by scanning physical memory for EPROCESS pool tags (typically 'Pro' and 'Proc') using Volatility's pool scanner. This allows it to find hidden processes that have been unlinked from PsActiveProcessHead, as well as processes in less obvious states. It is the recommended plugin when checking for DKOM-based rootkits or when pslist/pstree results seem incomplete.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.