Skip to content

Glossary

Volatility 3

Volatility 3 is the open source Python 3 memory forensics framework used to analyse Linux, Windows and macOS RAM images through symbol-driven plugins.

Volatility 3 is the current generation of the Volatility memory forensics framework (github.com/volatilityfoundation/volatility3), rewritten in Python 3. It reconstructs operating system structures from a raw memory image so an analyst can list processes, sockets, open files, loaded kernel modules and more, without trusting anything on the compromised host.

Unlike Volatility 2, it has no profiles. It relies on symbol tables in ISF (Intermediate Symbol Format) JSON. For Linux these are generated with dwarf2json from a debug vmlinux and the matching System.map, and the kernel is identified from the image with banners.Banners. Plugins are namespaced by operating system:

vol -f mem.lime banners.Banners
vol -s ./symbols -f mem.lime linux.pstree.PsTree
vol -s ./symbols -f mem.lime linux.bash.Bash

Commonly used Linux plugins include linux.pslist.PsList, linux.psaux.PsAux, linux.lsof.Lsof, linux.sockstat.Sockstat, linux.malfind.Malfind, linux.lsmod.Lsmod, linux.check_modules.Check_modules and linux.check_syscall.Check_syscall. The most frequent obstacle is a missing or mismatched symbol table, which produces errors or empty output. See Linux memory forensics with LiME and Volatility.