volatility3
Framework for analyzing volatile memory
Volatility is the world's most widely used framework for extracting digital artifacts from volatile memory (RAM) samples. The extraction techniques are performed completely independent of the system being investigated but offer visibility into the runtime state of the system.
homepage ↗homepage ↗ github: volatilityfoundation/volatility3 pypi: volatility3
Available in
| Overlay | Newest | Ebuilds | Last activity | |
|---|---|---|---|---|
| gentoo gitweb ↗ | 2.28.0 | 2 | 17 h | details › |
Versions & arches
Use flags of 2.28.0
- crypt support plugins that decrypt passwords, password hashes, etc.
- disasm support plugins that perform malware analysis and disassemble code
- jsonschema improve error messages regarding improperly configured ISF files
- leechcore support memory acquisition via leechcore
- snappy support AVMLs native compression format
- test Enable dependencies and/or preparations necessary to run tests (usually controlled by FEATURES=test but can be toggled independently)
- yara support YARA pattern matching engine
3 expansion flags (python targets, ABIs, cpu flags…)
- python_targets_python3_12
- python_targets_python3_13
- python_targets_python3_14
Runtime dependencies of 2.28.0
show 32 lines
crypt?
(
)
disasm?
(
)
jsonschema?
(
)
leechcore?
(
)
snappy?
(
)
yara?
(
||
(
)
)
python_targets_python3_12?
(
)
python_targets_python3_13?
(
)
python_targets_python3_14?
(
)