crwdns2933423:0crwdne2933423:0
crwdns2935033:0Volatilitycrwdne2935033:0

Volatility

Volatility is a memory forensics tool made for analyzing data captured from a computers RAM modules.

Type Part # Supplier URL
Memory Forensics Tool Volatility Foundation https://www.volatilityfoundation.org

Background Information

Volatility is a memory forensics tool made for analyzing data captured from a computers RAM modules. Captures can be used to determine all sorts of things about the state of a system when the memory capture was made including

  • Cached files
  • Cached RSA private/public keys
  • Clipboard contents
  • Command history
  • Driver/kernel module details
  • Keyboard buffer contents
  • Open sockets
  • Registry contents
  • Running processes
  • Shellbags

Additional Information

crwdns2931311:0crwdne2931311:0(1)

How to analyze RAM through Kali Linux Forensics mode

crwdns2944524:01crwdne2944524:0

crwdns2936625:0crwdne2936625:0:

crwdns2936751:024crwdne2936751:0 0

crwdns2936753:07crwdne2936753:0 0

crwdns2936753:030crwdne2936753:0 2

crwdns2942667:0crwdne2942667:0 50