
Interactive DFIR walkthrough of CVE-2026-31431 (Copy Fail) - from SIEM alert to confirmed verdict. Real Volatility 3 commands, verified methodology.
An interactive, step-by-step forensic investigation walkthrough for the Copy Fail Linux kernel vulnerability (CVE-2026-31431).
Click through a realistic incident response scenario — from SIEM alert to confirmed verdict — using real tools and verified commands.

linux.pagecache.Files, linux.pagecache.InodePages)ausearch syntaxstrings on a memory dumpCopy Fail (CVE-2026-31431) is a page-cache-only attack — disk forensics alone will miss it entirely. This walkthrough shows what a DFIR analyst would actually look for.
Single-page HTML with React (via CDN). No build step, no dependencies — just open index.html.
🧪 Periodic Table of DFIR — 118 tools for Digital Forensics & Incident Response
Marino Bekios — MB Labs
MIT - © 2026 Marino Bekios, MB Labs