CHFI Storage Forensics and File System Analysis Practice Question
In a memory forensics investigation using Volatility, an analyst wants to see a list of processes that were active at the time of acquisition, including hidden processes. Which Volatility command should be used?
⚠ Common exam trap
Many exam-takers confuse pslist (which lists only linked processes) with psscan (which finds hidden processes), mistakenly believing pslist can detect all active processes because it is the most commonly used command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
psscan
Psscan, because it scans the physical memory for _EPROCESS structures, allowing it to detect processes that are hidden from the standard linked list used by pslist. This makes psscan the appropriate command for identifying hidden or unlinked processes that were active at the time of acquisition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pslist
Why it's wrong here
pslist walks the kernel's doubly-linked list of EPROCESS objects starting from PsActiveProcessHead. Because it relies on this active list, any process that a rootkit unlinks to hide itself will simply not appear in the output. It also doesn't scan memory for orphaned structures, making it ineffective against common direct kernel object manipulation (DKOM) attacks.
- ✗
pstree
Why it's wrong here
pstree builds a parent-child hierarchy by traversing the same PsActiveProcessHead linked list used by pslist, so it inherits exactly the same blind spot for unlinked processes. While it adds valuable relationship information, it cannot expose hidden or detached EPROCESS objects that are no longer reachable from the list head. Thus it is just as vulnerable as pslist to hidden-process evasion.
- ✗
netscan
Why it's wrong here
netscan is a network artifact plugin that enumerates TCP/UDP connections and listening sockets by scanning for network-related pool structures, not processes. It tells you that some process has a connection, but it does not provide a complete, authoritative list of running processes. Even if a process has no network activity, it would be absent from netscan output, so it cannot answer the question 'what processes are running?'
- ✓
psscan
Why this is correct
psscan bypasses the linked list entirely by scanning physical memory for EPROCESS pool tags (typically 'Pro' and 'Proc') using Volatility's pool scanner. This allows it to find hidden processes that have been unlinked from PsActiveProcessHead, as well as processes in less obvious states. It is the recommended plugin when checking for DKOM-based rootkits or when pslist/pstree results seem incomplete.
Go deeper
Related to this question
Learn chapter
Overview of Computer Forensics and Investigation Process
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
RAM Analysis
RAM Analysis is the forensic examination of a computer’s volatile memory to uncover evidence of running processes, network connections, malware, and user activity that is lost when the system is powered off.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.