mandiant / mandiant/VM-Packages

Package proposal: volatility.vm

Open
#189 2 comments 0 reactions 0 assignees View on GitHub
:cyclone: COMMANDO-VM :new: package
Dominant language
PowerShell
Stars
246
Forks
98
Avg merge
9h 30m
Merged PRs (30d)
7

Description

### Package Name

volatility

### Tool Name

Volatility

### Package type

ZIP_EXE

### Tool's version number

2.6

### Category

Forensic

### Tool's authors

The Volatility Foundation

### Tool's description

The Volatility Framework is a completely open collection of tools, implemented in Python under the GNU General Public License, for the extraction of digital artifacts from volatile memory (RAM) samples. The extraction techniques are performed completely independent of the system being investigated but offer visibility into the runtime state of the system. The framework is intended to introduce people to the techniques and complexities associated with extracting digital artifacts from volatile memory samples and provide a platform for further work into this exciting area of research.

### Download URL

https://downloads.volatilityfoundation.org/releases/2.6/volatility_2.6_win64_standalone.zip

### Download SHA256 Hash

bb021f3b569bf8ee4a408b2e07b0662699894ff7eecd4473badf0ef0c58f2fce

### Why is this tool a good addition?

Volatility is a very powerful tool for Memory Forensics as well as Malware Analysis.
It is able to read memory dump to perform listing of running processes, network connection, .dll files, file handles, scanning of malware using YARA rules.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing existing package definitions in VM-Packages to determine how a ZIP_EXE proposal is represented. Use the Volatility 2.6 download URL and SHA256 hash from this issue; done means the Volatility package is added with the specified metadata and can be retrieved with the recorded checksum.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
reverse-engineering, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.