A Memory Forensics RAM discovery tool.

Installation

git clone https://github.com/volatilityfoundation/volatility3.git
cd volatility3
pip install --user -e ".[full]"

Concepts

Usage

python3 vol.py -f <FILE> <PLUGIN_NAME> (<PLUGIN_OPTION>)

Windows Plugins

Extra