基于Memprocfs和Volatility的可视化内存取证工具
-
Updated
Jun 24, 2026 - Python
基于Memprocfs和Volatility的可视化内存取证工具
Project containing several tools/ scripts to recover the OpenSSH session keys used to encrypt/ decrypt SSH traffic.
Volatility3 Linux profiles
Volatility, on Docker 🐳
Generate Volatility3 profiles from BTF.
PyDFIRRam is a Python library leveraging Volatility 3 to simplify and enhance memory forensics. It streamlines the research, parsing, and analysis of memory dumps, allowing users to focus on data rather than commands.
This project is for DFIR that wants to speed up some memory forensic analysis
Skalle is a handy add-on for Volatility that lets you run it in a graphical user interface. It also adds some cool features!
Linux BPF plugins for Volatility3
Volatility3 plugin to validate Authenticode-signed processes, either with embedded signature or catalog-signed
A suite of Volatility 3 plugins for memory forensics of Docker containers
Volatility 3 plugins to extract a module as complete as possible
My Linux profiles built for Volatility 2/3
M3MX Unified memory forensics workbench powered by Volatility manual & automated analysis, MITRE ATT&CK mapping, and an AI agent, all in your browser.
Volatility3 plugin to calculate and compare Windows processes fuzzy hashes
Volatility 3 plugin for extracting BitLocker Full Volume Encryption Keys (FVEK)
Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage.
Linux symbols creation tool for Volatility3
Volatility-CheatSheet
Add a description, image, and links to the volatility3 topic page so that developers can more easily learn about it.
To associate your repository with the volatility3 topic, visit your repo's landing page and select "manage topics."