Security

Volatility – advanced memory forensics framework

The Volatility Framework is a completely open collection of tools, implemented in Python, for the extraction of digital artifacts from volatile memory (RAM) samples.

The extraction techniques are performed completely independent of the system being investigated but offer visibility into the runtime state of the system. The framework is intended to introduce people to the techniques and complexities associated with extracting digital artifacts from volatile memory samples and provide a platform for further work into this exciting area of research.

Volatility was designed by forensics, incident response, and malware experts to focus on the types of tasks these analysts typically form.

Key Features

  • Single, cohesive framework analyzes RAM dumps from 32- and 64-bit windows, linux, mac, and android systems. Volatility’s modular design allows it to easily support new operating systems and architectures as they are released.
  • Carving.
  • Command histories.
  • Console input/output buffers.
  • USER objects (GUI memory).
  • Network related data structures.
  • Extensible and scriptable API.
  • Fast and efficient algorithms let you analyze RAM dumps from large systems without unnecessary overhead or memory consumption.
  • Supports a variety of sample file formats and the ability to convert between these formats:
    • Raw linear sample (dd).
    • Hibernation file (from Windows 7 and earlier).
    • Crash dump file.
    • VirtualBox ELF64 core dump.
    • VMware saved state and snapshot files.
    • EWF format (E01).
    • LiME format.
    • Mach-O file format.
    • QEMU virtual machine dumps.
    • Firewire HPAK (FDPro).
  • Cross-platform support – runs under Linux, Mac OS X, and Windows.

Website: www.volatilityfoundation.org
Support: Documentation Project, GitHub Code Repository
Developer: Volatility Foundation
License: GNU General Public License v2.0

Volatility is written in Python. Learn Python with our recommended free books and free tutorials.


Related Software

Digital Forensics Tools
GRR Rapid ResponseRemote live forensics for incident response
Radare2Portable reversing framework
The Sleuth KitCollection of tools for forensic analysis
MemProcFSView physical memory as files in a virtual file system
Autopsy Forensic BrowserGraphical interface to SleuthKit
iaitoOfficial graphical interface for radare2
ChainsawFast forensic triage and threat hunting tool for Windows artefacts
VelociraptorEndpoint visibility and collection tool
TimesketchCollaborative forensic timeline analysis
PlasoPython-based digital forensics framework
VolatilityAdvanced memory forensics framework
UACCollect forensic artefacts from Linux and other Unix-like systems
IPEDProcess, index and analyse large collections of digital evidence
guymagerForensic imaging tool based on Qt
DissectAccess and query evidence across disk images and file systems
dcflddEnhanced version of dd for forensics and security
rddForensic copy program
JomonNetwork forensics and passive sniffer
Mozilla InvestiGatorReal-time digital forensics and investigation platform

Read our verdict in the software roundup.

Forensics Memory Tools
MemProcFSView physical memory as files in a virtual file system
pypykatzPython implementation of Mimikatz
PCILeechSecurity research and memory acquisition tool
VolatilityAdvanced memory forensics framework
AVMLAcquire Volatile Memory for Linux
VolshellCLI tool for working with memory
LeechCorePhysical memory acquisition library
EVTXtractRecovers and reconstructs fragments of EVTX log files
mquireMemory forensics and analysis tool
LEMONMemory acquisition utility
yarpYet Another Registry Parser
emdCommand line memory acquisition tool for Linux systems
AutoTimelinerExtract forensic timeline from volatile memory dump

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our carefully curated directory of recommended free and open source software, covering every major software category.

The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more.

Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form.
Subscribe

Please read our Comment Policy before commenting.

Notify of
guest
0 Comments
Oldest
Newest Most Voted