Volatility Framework

Volatility is a complete set of open source tools used for advanced memory forensics analysis. It works best on 32 bits Windows machine. Once we have the memory image of the compromised system. we can use Volatility to perform the investigation. For the download and installation , follow this link https://www.volatilesystems.com/default/volatility

Volatility Framework command line interface

Another aspect of this tool is that it can be used to hunt malware hidden in the memory

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s