An advanced memory forensics framework
-
Updated
May 16, 2025 - Python
An advanced memory forensics framework
Volatility 3.0 development
Volatility plugins developed and maintained by the community
volatility explorer (volatility 2)
Volatility Explorer Suit (volatility 3)
Volatility Framework plugin to detect various types of hooks as performed by banking Trojans
ETW forensic tool for Volatility3 plugin
Neural network framework for volatility surface approximation and calibration. Supports rough Heston/Bergomi, random grids, multi-regime architectures.
Enhancing RAM Investigation with LLM and RAG
A tool to automate memory dump processing using Volatility, including optional Splunk integration.
DigDog-基于深度学习和内存取证技术的恶意软件检测框架
DQuant is an open-source Python library for automated volatility forecasting of financial time series.
GLASS (Global Language And Site Scanner) is a Volatility plugin designed by Clayton Wenzel, James Baumhardt, and Nathan Eberly, aiming to swiftly identify and classify malicious domains and unexpected languages within a memory dump, providing users with dynamic insights for forensic investigations.
Volatility plugins to recover ML model attributes from memory images
A modular Python toolkit for advanced options pricing, volatility modeling, Greeks computation, and risk analysis. Includes Monte Carlo and Black-Scholes models, machine learning volatility surfaces, and interactive visualizations via Streamlit.
Run several volatility 3 plugins at the same time (Supports containrized processing)
AutoMem is an AI agent specifically built for memory dumps forensics. It is built using DeepAgents framework from LangChain with the integration of Volatility 3 plugins in the MCP server. Ollama acts as the local LLM provider to provide privacy first analysis in local offline environment.
MCP (Model Context Protocol) interface for Volatility 3, providing memory forensics capabilities through LLM-based tools. Query, analyze, and automate Volatility 3 plugins using natural language via API or agent-based workflows
A Python2 GUI tool to automate memory dump analysis using Volatility 2.6.1. It allows users to load memory files, automatically detects the correct profile with imageinfo, and runs common forensic commands. Results are organized into case folders for easy review.
To associate your repository with the volatility-framework topic, visit your repo's landing page and select "manage topics."