基于Memprocfs���Volatility的可视化内存取证工具
-
Updated
Aug 10, 2026 - TypeScript
基于Memprocfs���Volatility的可视化内存取证工具
Project containing several tools/ scripts to recover the OpenSSH session keys used to encrypt/ decrypt SSH traffic.
Volatility3 Linux profiles
Decrypt VMware vTPM-encrypted .vmem/.vmsn/.vmss/.nvram from the VM password, and flatten the .vmem to a Volatility-ready image.
Volatility, on Docker 🐳
This project is for DFIR that wants to speed up some memory forensic analysis
Generate Volatility3 profiles from BTF.
PyDFIRRam is a Python library leveraging Volatility 3 to simplify and enhance memory forensics. It streamlines the research, parsing, and analysis of memory dumps, allowing users to focus on data rather than commands.
Skalle is a handy add-on for Volatility that lets you run it in a graphical user interface. It also adds some cool features!
Linux BPF plugins for Volatility3
Volatility3 plugin to validate Authenticode-signed processes, either with embedded signature or catalog-signed
A suite of Volatility 3 plugins for memory forensics of Docker containers
Volatility 3 plugins to extract a module as complete as possible
My Linux profiles built for Volatility 2/3
M3MX Unified memory forensics workbench powered by Volatility manual & automated analysis, MITRE ATT&CK mapping, and an AI agent, all in your browser.
Volatility 3 plugin for extracting BitLocker Full Volume Encryption Keys (FVEK)
Volatility-CheatSheet
Volatility3 plugin to calculate and compare Windows processes fuzzy hashes
Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage.
To associate your repository with the volatility3 topic, visit your repo's landing page and select "manage topics."