Skip to content
pagefile.sys forensics

Windows Pagefile.sys Parser

Forensic analysis of Windows pagefile.sys — carve files, extract strings and indicators of compromise. Streams page-by-page so multi-GB files stay on your device.

Files are processed entirely in your browser with WebAssembly. Nothing is uploaded.

pagefile.sys · 8.00 GBLocal only
Null / unusedText-heavyPE executableXpress-Huffman compressedSQLite databaseHigh entropy (encrypted?)

Illustration — each band is a page class, sized by its share of the file.

Drop pagefile.sys, swapfile.sys, a triage ZIP or a collection folder

Everything stays on this device. Multi-GB files and ZIP collections (KAPE, Velociraptor) are streamed, never uploaded.

Synthetic pagefile of a fictional intrusion (FIN-WKS-07) — no real data. Includes carved event-log records: try the time range.

pagefile.sys · swapfile.sys · .zip · folders

How to get your data

Windows keeps pagefile.sys locked while it runs, so a normal copy fails. Here is the fastest way to grab it.

  1. Collect pagefile.sys
  2. Drop the file, folder or ZIP above
  3. Everything stays in your browser — nothing is uploaded

Live Windows host. Open cmd with Run as administrator in the folder that holds RawCopy.exe (free, open source, no install). E: is your external or evidence drive.

cmd · admin
mkdir E:\triage 2>nul & RawCopy.exe /FileNamePath:C:\pagefile.sys /OutputPath:E:\triage & RawCopy.exe /FileNamePath:C:\swapfile.sys /OutputPath:E:\triage

You get E:\triage\pagefile.sys and swapfile.sys (Windows 8+): drop both here. RawCopy ↗

No command line? FTK Imager

FileAdd Evidence ItemLogical DriveC:\[root]pagefile.sysExport Files…

Run FTK Imager as administrator, follow the path above and export to E:\triage. It reads the raw volume, so the lock does not matter.

Gotchas

  • Copy, robocopy and shadow copies don't work on a live system: the file is locked and Volume Shadow Copies exclude it. You need admin rights and a raw NTFS reader (RawCopy, KAPE, FTK Imager, Velociraptor).
  • It is volatile: collect before any reboot or shutdown (Windows may wipe it at shutdown), and write to an external drive, never to C:.
  • KAPE MemoryFiles only looks at C:\. If the registry lists paging files on other volumes, copy them too.
Full acquisition guide →
uploaded — the file never leaves your device
0 B
streaming chunks, so 16 GB pagefiles fit
16 MB
page classes: signatures + entropy buckets
20
indicator families swept over every string
10
01 — What it extracts

What this Windows pagefile.sys parser extracts

Three layers of analysis run as the file streams past — signature carving, string extraction, and artifact regex sweeps.

Per-page signature carving

Every 4 KB page is matched against PE (MZ + PE\0\0), registry hive base block (regf) and bin (hbin), MFT record (FILE/BAAD), SQLite, EVTX (ElfFile/ElfChnk), Prefetch (SCCA), LNK shell link, PNG/JPEG/PDF/ZIP, XML/JSON, and Xpress-Huffman compressed pages.

ASCII and UTF-16LE strings

Configurable minimum-length string extraction across the entire file, with cross-chunk continuation so runs that straddle 16 MB chunk boundaries are still captured. Every string carries its absolute file offset.

Regex artifact sweeps

URLs, e-mails, IPv4 and IPv6 addresses, Windows paths (C:\…), UNC paths, registry keys (HKLM, HKCU…), GUIDs, command-line indicators (cmd.exe, powershell, mshta, rundll32, certutil…), and credential heuristics (password=, Bearer tokens, JWT shapes).

Statistical fallback

Pages without a signature get bucketed by Shannon entropy, null-byte ratio and printable ratio so analysts still see complete coverage of the file — including likely-encrypted high-entropy regions.

02 — Workflow

How to analyze a Windows pagefile.sys

  1. 1

    Acquire pagefile.sys

    Take a forensic copy of pagefile.sys from a shut-down system, a disk image, or the raw NTFS volume. Windows keeps the file open and locked while running.

  2. 2

    Open this page in your browser

    No installation needed — the analyzer is a Rust program compiled to WebAssembly that runs entirely client-side.

  3. 3

    Drop the file or browse to it

    Files of any size are supported. The browser streams the file in 16 MB chunks; the full file never lives in memory at once.

  4. 4

    Review the four result tabs

    Overview shows the page-type histogram and counts. Page map lists every classified page (PE, registry, MFT, SQLite, etc.). Strings is a searchable list of ASCII + UTF-16LE strings. Artifacts groups extracted URLs, e-mails, IPs, paths, registry keys, GUIDs, command-lines and credential indicators.

  5. 5

    Export findings

    Download the full report as JSON, the strings as TXT, or the artifacts as CSV for follow-up in your forensic toolkit.

03 — Field notes

Learn more about pagefile.sys forensics

Background reading on the file format, the techniques this tool uses, and what you can and can't recover.

Frequently asked questions

What is pagefile.sys?

pagefile.sys is the file Windows uses as the on-disk extension of physical RAM. When memory is tight, the Memory Manager writes cold pages to this file so the freed RAM can serve hotter workloads.

Is my file uploaded?

No. The analyzer runs in your browser via WebAssembly. The bytes of your pagefile never leave the device — there is no server-side processing and no telemetry.

What can this parser extract from a pagefile?

Per-page classification by magic bytes (PE images, registry hive blocks, MFT records, SQLite databases, EVTX chunks, Prefetch, LNK, PNG/JPEG/PDF/ZIP, Xpress-Huffman compressed pages), ASCII and UTF-16LE strings with absolute offsets, and regex artifacts: URLs, e-mails, IPv4/IPv6, Windows paths, UNC paths, registry keys, GUIDs, command-line indicators, and credential heuristics.

What file size is supported?

Multi-gigabyte pagefiles (4 GB, 8 GB, 16 GB and beyond) are supported. The Web Worker reads the file in 16 MB chunks via File.slice() so the browser never needs to hold the full file in memory.

Does it work with Windows 10 / 11 compressed memory?

Pages compressed by CompressionStoreManager (Xpress-Huffman, CompressionFormat 4) are detected and flagged so analysts know what's hiding. Full decompression is a future enhancement.

Can I correlate pages back to a specific process?

Not from the pagefile alone. Mapping a page slot to a process and virtual address lives in page-table entries (PTEs) in RAM — that requires a paired memory dump (Volatility / MemProcFS). Standalone pagefile analysis gives content, not context.

What's the difference between pagefile.sys, swapfile.sys and hiberfil.sys?

pagefile.sys is the default backing store for paged anonymous memory. swapfile.sys holds working sets of UWP / Modern apps. hiberfil.sys is a full RAM snapshot written at hibernation. Each can yield different artifacts.

Paged-out memory, surfaced in minutes.

Drop pagefile.sys, swapfile.sys or a whole triage collection. Parsing runs in WebAssembly on this device — close the tab and nothing is left behind.

Try the parser