Zer0Byte

Geekiest Techno News

Volatility An advanced memory forensics framework

Warning NOOBs
This tool is just aint for u :p

Fellow geeks, i present you the future of ram dumps. I haven’t seen any ram dumping tool as detailed as this one here (stupid google dint find any thing better than this ;P or maybe the developers of volatility are really good in seo :p )

According to the developers

The Volatility Framework is a completely open collection of tools, implemented in Python under the GNU General Public License, for the extraction of digital artifacts from volatile memory (RAM) samples. The extraction techniques are performed completely independent of the system being investigated but offer unprecedented visibilty into the runtime state of the system. The framework is intended to introduce people to the techniques and complexities associated with extracting digital artifacts from volatile memory samples and provide a platform for further work into this exciting area of research.

Anyways this ram stalker has really cool crazy features like

  • Image Identification
    • imageinfo
    • datetime
    • kdbgscan
    • kprcscan
  • Processes and DLLs
    • pslist
    • pstree
    • psscan
    • dlllist
    • dlldump
    • handles
    • getsids
    • verinfo
  • Process Memory
    • memmap
    • memdump
    • procmemdump
    • procexedump
    • vadwalk
    • vadtree
    • vadinfo
    • vaddump
  • Kernel Memory and Objects
    • modules
    • modscan
    • moddump
    • ssdt
    • driverscan
    • filescan
    • mutantscan
    • thrdscan
  • Networking
    • connections
    • connscan
    • sockets
    • sockscan
    • netscan
  • Registry
    • hivescan
    • hivelist
    • printkey
    • hivedump
    • hashdump
    • lsadump
    • userassist
  • Crash Dumps, Hibernation, and Conversion
    • crashinfo
    • hibinfo
    • imagecopy
  • Malware and Rootkits
    • malfind
    • svcscan
    • ldrmodules
    • impscan
    • apihooks
    • idt
    • gdt
    • threads
    • callbacks
    • driverirp
    • devicetree
    • psxview
    • ssdt_ex

hehehe sorry for that stupid long list. I admit that i copied from developers website .

If  you think your are old enough to handle this tool then kindly download it.

Download Link

Note:- i wasted more than 30 minutes just to figure out why its not working, later i found out that there are 6 Prerequisites required just to run this program. Please read the “full installation Guide”. ( Thats why noobs i warned you in advance )

Related links

 

 

 

Categories: Linux, Tools, TOP NEWS, Windows