The Volatility Framework is a completely open collection of tools, implemented in Python, for the extraction of digital artifacts from volatile memory (RAM) samples.
The extraction techniques are performed completely independent of the system being investigated but offer visibility into the runtime state of the system. The framework is intended to introduce people to the techniques and complexities associated with extracting digital artifacts from volatile memory samples and provide a platform for further work into this exciting area of research.
Volatility was designed by forensics, incident response, and malware experts to focus on the types of tasks these analysts typically form.
Key Features
- Single, cohesive framework analyzes RAM dumps from 32- and 64-bit windows, linux, mac, and android systems. Volatility’s modular design allows it to easily support new operating systems and architectures as they are released.
- Carving.
- Command histories.
- Console input/output buffers.
- USER objects (GUI memory).
- Network related data structures.
- Extensible and scriptable API.
- Fast and efficient algorithms let you analyze RAM dumps from large systems without unnecessary overhead or memory consumption.
- Supports a variety of sample file formats and the ability to convert between these formats:
- Raw linear sample (dd).
- Hibernation file (from Windows 7 and earlier).
- Crash dump file.
- VirtualBox ELF64 core dump.
- VMware saved state and snapshot files.
- EWF format (E01).
- LiME format.
- Mach-O file format.
- QEMU virtual machine dumps.
- Firewire HPAK (FDPro).
- Cross-platform support – runs under Linux, Mac OS X, and Windows.
Website: www.volatilityfoundation.org
Support: Documentation Project, GitHub Code Repository
Developer: Volatility Foundation
License: GNU General Public License v2.0
Volatility is written in Python. Learn Python with our recommended free books and free tutorials.
Related Software
| Digital Forensics Tools | |
|---|---|
| GRR Rapid Response | Remote live forensics for incident response |
| Radare2 | Portable reversing framework |
| The Sleuth Kit | Collection of tools for forensic analysis |
| MemProcFS | View physical memory as files in a virtual file system |
| Autopsy Forensic Browser | Graphical interface to SleuthKit |
| iaito | Official graphical interface for radare2 |
| Chainsaw | Fast forensic triage and threat hunting tool for Windows artefacts |
| Velociraptor | Endpoint visibility and collection tool |
| Timesketch | Collaborative forensic timeline analysis |
| Plaso | Python-based digital forensics framework |
| Volatility | Advanced memory forensics framework |
| UAC | Collect forensic artefacts from Linux and other Unix-like systems |
| IPED | Process, index and analyse large collections of digital evidence |
| guymager | Forensic imaging tool based on Qt |
| Dissect | Access and query evidence across disk images and file systems |
| dcfldd | Enhanced version of dd for forensics and security |
| rdd | Forensic copy program |
| Jomon | Network forensics and passive sniffer |
| Mozilla InvestiGator | Real-time digital forensics and investigation platform |
Read our verdict in the software roundup.
| Forensics Memory Tools | |
|---|---|
| MemProcFS | View physical memory as files in a virtual file system |
| pypykatz | Python implementation of Mimikatz |
| PCILeech | Security research and memory acquisition tool |
| Volatility | Advanced memory forensics framework |
| AVML | Acquire Volatile Memory for Linux |
| Volshell | CLI tool for working with memory |
| LeechCore | Physical memory acquisition library |
| EVTXtract | Recovers and reconstructs fragments of EVTX log files |
| mquire | Memory forensics and analysis tool |
| LEMON | Memory acquisition utility |
| yarp | Yet Another Registry Parser |
| emd | Command line memory acquisition tool for Linux systems |
| AutoTimeliner | Extract forensic timeline from volatile memory dump |
Read our verdict in the software roundup.
Explore our carefully curated directory of recommended free and open source software, covering every major software category.The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more. Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form. |


Please read our Comment Policy before commenting.