Apocrypha

volatility3

Framework for analyzing volatile memory

Volatility is the world's most widely used framework for extracting digital artifacts from volatile memory (RAM) samples. The extraction techniques are performed completely independent of the system being investigated but offer visibility into the runtime state of the system.

Available in

OverlayNewestEbuildsLast activity
gentoo gitweb ↗ 2.28.0 2 17 h details ›

Versions & arches

VersionOverlay amd64x86 Committed
2.28.0 gentoo amd64 stable x86 stable view · download · history ↗
2.27.0 gentoo amd64 stable x86 stable view · download · history ↗

Use flags of 2.28.0

  • crypt support plugins that decrypt passwords, password hashes, etc.
  • disasm support plugins that perform malware analysis and disassemble code
  • jsonschema improve error messages regarding improperly configured ISF files
  • leechcore support memory acquisition via leechcore
  • snappy support AVMLs native compression format
  • test Enable dependencies and/or preparations necessary to run tests (usually controlled by FEATURES=test but can be toggled independently)
  • yara support YARA pattern matching engine
3 expansion flags (python targets, ABIs, cpu flags…)
  • python_targets_python3_12
  • python_targets_python3_13
  • python_targets_python3_14

Runtime dependencies of 2.28.0

show 32 lines