• GitHub
  • Contact
The Volatility Foundation - Promoting Accessible Memory Analysis Tools Within the Memory Forensics Community
  • The Volatility Framework
  • Training
  • Events
  • FAQ
  • Contest
  • About
  • Blog
Select Page

Volatility 2.4 at Blackhat Arsenal – Reverse Engineering Rootkits

by Volatility | Aug 27, 2014 | arsenal, blackhat, kernel, rootkits, volatility

This video demonstrates how you can leverage Volatility and memory forensics to detect kernel rootkits, assist with reverse engineering, and use the results for developing additional indicators. The video is narrated by Apple’s text to speech and you can find...

Volatility 2.4 at Blackhat Arsenal – Tracking Mac OS X User Activity

by Volatility | Aug 21, 2014 | arsenal, blackhat, forensics, macosx, volatility

This demo shows how to track Mac OS X user activity by examining artifacts in physical memory with Volatility.  The video is narrated by Apple’s text to speech and you can find the actual text on the Youtube page. The live/in-person demo was given at...

New Volatility 2.4 Cheet Sheet with Linux, Mac, and RTFM

by Volatility | Aug 18, 2014 | artofmemoryforensics, linux, macosx, training, volatility, windows

Our Windows Malware and Memory Forensics Training class is intense and rigorous, because its designed to reflect real world investigations. When you have a limited amount of time and you’re being pressured for reliable answers – every minute counts....

New Paper: In Lieu of Swap: Analyzing Compressed RAM in Mac OS X and Linux

by Volatility | Aug 14, 2014 | linux, macosx, volatility

A research paper (slides here) ( X dfrws.org/2014/proceedings/presentations/DFRWS2014-p1.pdf) that I worked on with Golden G. Richard was recently published at DFRWS 2014 ( X dfrws.org/2014/program.shtml) and received the Best Paper award! The paper, In Lieu of Swap:...

Presenting Volatility Foundation Volatility Framework 2.4

by Volatility | Aug 13, 2014 | artofmemoryforensics, blackhat, kernel, linux, macosx, malware, truecrypt, volatility, win8

The release of this new Volatility version coincides with the publication of The Art of Memory Forensics. It adds support for Windows 8, 8.1, 2012, and 2012 R2 memory dumps, Mac OS X Mavericks (up to 10.9.4), and Linux kernels up to 3.16. New plugins include the...
« Older Entries

Volatility Blog Archive

2025

  • + July (1)
  • + May (2)
  • + March (1)

2024

  • + August (1)
  • + July (1)
  • + March (1)

2023

  • + August (1)
  • + July (1)
  • + June (1)
  • + March (1)
  • + February (1)
  • + January (1)

2022

  • + July (1)
  • + February (1)
  • + January (1)

2021

  • + October (1)
  • + August (1)
  • + May (1)
  • + January (1)

2020

  • + November (1)
  • + May (2)

2019

  • + November (1)
  • + October (2)
  • + July (1)
  • + June (1)

2018

  • + November (2)
  • + May (1)
  • + February (1)

2017

  • + November (1)
  • + June (1)
  • + April (1)

2016

  • + December (2)
  • + September (1)
  • + August (2)
  • + July (1)
  • + April (3)

2015

  • + November (2)
  • + October (1)
  • + August (2)
  • + July (2)
  • + June (1)
  • + May (1)
  • + March (1)
  • + February (1)
  • + January (1)

2014

  • + December (1)
  • + October (3)
  • + September (5)
  • + August (6)
  • + July (2)
  • + May (1)
  • + April (2)
  • + February (2)
  • + January (5)

2013

  • + October (3)
  • + September (2)
  • + August (1)
  • + June (9)
  • + May (15)
  • + April (2)
  • + March (2)
  • + February (1)
  • + January (4)

2012

  • + December (2)
  • + November (1)
  • + October (14)
  • + September (19)
bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

     

    Loading Comments...
     

    You must be logged in to post a comment.