Inside The Tunnel Without Walls: A Linux Memory Forensics Walkthrough

Join Hack The Box for a live, step-by-step walkthrough of a hard-rated Sherlock from Holmes CTF 2025. Investigate a compromised Linux server through its memory dump and uncover how the attacker manipulated the network around it.

Presented by Hack The Box

Holmes CTF 2026_Webinar_Inside The Tunnel Without Walls - A Linux Memory Forensics Walkthrough__Hero_1920x1080

HACK THE BOX WEBINAR FOR BLUE TEAMS

8 September 2026

  • 2 PM UTC
  • Online
  • Free

Overview

A Linux memory dump can expose what disk artifacts and alerts miss: active processes, covert connections, fake services, and traces of an attacker working across the network.

In this technical session, Hack The Box experts will walk through The Tunnel Without Walls, a Sherlock originally featured in Holmes CTF 2025. Starting with the creation of a Volatility3 symbol table, they will investigate a memory dump from a connected Linux server and follow the evidence behind unusual redirects, spoofed network services, and a wider supply-chain attack.

With Holmes CTF 2026 taking place from September 17–21, this session is the perfect warm-up. You’ll see how a Sherlock investigation unfolds on the HTB platform while sharpening the memory forensics and incident response skills you’ll need to take on this year’s defensive challenges.

What you will learn

  • Linux memory forensics: Examine a Linux memory image and identify the processes, services, and artifacts that matter to the investigation.
  • Volatility3 symbol tables: Understand how to create and use the correct symbols for analyzing a Linux memory dump.
  • Network manipulation: Trace covert connections, unusual redirects, and evidence of DHCP and DNS spoofing.
  • Attack reconstruction: Connect individual artifacts to reveal the attacker's motivation and the wider supply-chain compromise.