Skip to content

Volatility Framework

Definition

An open-source memory forensics framework written in Python. It parses raw memory images using OS-specific symbol information to reconstruct kernel data structures and extract artefacts: process lists, network connections, loaded drivers, registry hives, injected code regions, and strings. Version 3 uses public symbol files and does not require pre-built profiles.

Category
Open-source memory forensics framework
Language
Python
Input
Raw memory images
Artefacts extracted
Processes, network connections, drivers, registry hives, injected code, strings
Version 3 change
Uses public symbol files, no pre-built profile required

Common questions

Why does Volatility need OS-specific symbol information at all?+

A raw memory image is just bytes; without knowing the exact offsets and layout of kernel data structures for the specific OS build, Volatility cannot locate the process list, handle tables, or network structures reliably, so symbol information tells it where those structures live in that build's memory layout.

Can Volatility recover data an attacker tried to hide by terminating a process?+

Sometimes. If the memory image was captured before the pages were overwritten or reused, remnants of a terminated process's data can persist and be recovered, but this is not guaranteed since the operating system reallocates freed memory over time.

Related terms

LiME (Linux Memory Extractor)
A loadable kernel module that acquires physical memory from Linux, macOS, and Android systems. It maps the physical address space and either...
Order of Volatility
The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
Physical Memory Image
A byte-for-byte copy of all installed RAM on a running system, acquired at the hardware or kernel level. Contains all data structures,...
Process Injection
A technique used by malware and attackers to execute code inside the address space of a legitimate running process. Common methods include...
Reflective DLL Loading
A technique that loads a Windows DLL directly from memory without registering it with the OS loader. The DLL resolves its own...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.