An advanced memory forensics framework
-
Updated
May 16, 2025 - Python
An advanced memory forensics framework
Volatility 3.0 development
Volatility plugins developed and maintained by the community
volatility explorer
Volatility Explorer Suit
Volatility Framework plugin to detect various types of hooks as performed by banking Trojans
ETW forensic tool for Volatility3 plugin
A tool to automate memory dump processing using Volatility, including optional Splunk integration.
DigDog-基于深度学习和内存取证技术的恶意软件检测框架
Volatility plugins to recover ML model attributes from memory images
GLASS (Global Language And Site Scanner) is a Volatility plugin designed by Clayton Wenzel, James Baumhardt, and Nathan Eberly, aiming to swiftly identify and classify malicious domains and unexpected languages within a memory dump, providing users with dynamic insights for forensic investigations.
Enhancing RAM Investigation with LLM and RAG
MCP (Model Context Protocol) interface for Volatility 3, providing memory forensics capabilities through LLM-based tools. Query, analyze, and automate Volatility 3 plugins using natural language via API or agent-based workflows
Run several volatility 3 plugins at the same time (Supports containrized processing)
Volatility 3 plugin to extract the heap from Windows memory images
A Python2 GUI tool to automate memory dump analysis using Volatility 2.6.1. It allows users to load memory files, automatically detects the correct profile with imageinfo, and runs common forensic commands. Results are organized into case folders for easy review.
Add a description, image, and links to the volatility-framework topic page so that developers can more easily learn about it.
To associate your repository with the volatility-framework topic, visit your repo's landing page and select "manage topics."