• GitHub
  • Contact
The Volatility Foundation - Promoting Accessible Memory Analysis Tools Within the Memory Forensics Community
  • The Volatility Framework
  • Training
  • Events
  • FAQ
  • Contest
  • About
  • Blog
Select Page

MoVP II – 2.2 – Unloaded Windows Kernel Modules

by Volatility | May 22, 2013 | forensics, kernel, malware, movp, volatility, windows

Sometimes knowing which kernel modules recently unloaded can be as valuable as knowing which ones loaded. Windows keeps a record of drivers that unload for debugging purposes – in particular to help analyze failures in the attempt to call unloaded code. If...

Slides and Video of Analyzing Malware in Memory Webinar

by Volatility | Jan 4, 2013 | code injection, forensics, kernel, malware, volatility, windows

I recently presented a Hacker Academy Deep Dive ( X thehackeracademy.com/tha-deep-dive-analyzing-malware-in-memory/) webinar on ‘Analyzing Malware in Memory’. The purpose of this presentation was to show how in-depth malware analysis can performed on...

OMFW 2012: Mining the PFN Database for Malware Artifacts

by Volatility | Oct 19, 2012 | forensics, kernel, knttools, malware, omfw, windows

There are few people in the world who know more about physical memory acquisition and analysis than Mr. Garner; President of GMG Systems, Inc. and author of ( X http://www.gmgsystemsinc.com/knttools/) KnTTools. At a rare conference appearance, George discussed how he...

OMFW 2012: Datalore: Android Memory Analysis

by Volatility | Oct 12, 2012 | android, forensics, kernel, linux, omfw, volatility

This presentation went over the Android specific analysis capabilities of Volatility as well as showed how to use LiME to capture physical memory from Android devices. This functionality will be included in the 2.3 Volatility release. Author/Presenter: Joe Sylve /...

OMFW 2012: Analyzing Linux Kernel Rootkits with Volatility

by Volatility | Oct 12, 2012 | kernel, linux, malware, omfw, volatility

This presentation went over a number of the new Linux plugins and showed how to use them when investigating Linux kernel rootkits. All of the plugins and functionality shown is part of the 2.2 Volatility release. Author/Presenter: Andrew Case / @attrc  Direct Link:...

Phalanx 2 Revealed: Using Volatility to Analyze an Advanced Linux Rootkit

by Volatility | Oct 10, 2012 | kernel, malware, movp, volatility

Month of Volatility Plugins In this blog post I will analyze the Phalanax2 rootkit using both Volatility as well as traditional malware analysis techniques. Phalanx2 Phalanx2 (P2) is the latest version of a private rootkit, whose original source was leaked to...
« Older Entries
Next Entries »

Volatility Blog Archive

2026

  • + March (1)

2025

  • + July (1)
  • + May (2)
  • + March (1)

2024

  • + August (1)
  • + July (1)
  • + March (1)

2023

  • + August (1)
  • + July (1)
  • + June (1)
  • + March (1)
  • + February (1)
  • + January (1)

2022

  • + July (1)
  • + February (1)
  • + January (1)

2021

  • + October (1)
  • + August (1)
  • + May (1)
  • + January (1)

2020

  • + November (1)
  • + May (2)

2019

  • + November (1)
  • + October (2)
  • + July (1)
  • + June (1)

2018

  • + November (2)
  • + May (1)
  • + February (1)

2017

  • + November (1)
  • + June (1)
  • + April (1)

2016

  • + December (2)
  • + September (1)
  • + August (2)
  • + July (1)
  • + April (3)

2015

  • + November (2)
  • + October (1)
  • + August (2)
  • + July (2)
  • + June (1)
  • + May (1)
  • + March (1)
  • + February (1)
  • + January (1)

2014

  • + December (1)
  • + October (3)
  • + September (5)
  • + August (6)
  • + July (2)
  • + May (1)
  • + April (2)
  • + February (2)
  • + January (5)

2013

  • + October (3)
  • + September (2)
  • + August (1)
  • + June (9)
  • + May (15)
  • + April (2)
  • + March (2)
  • + February (1)
  • + January (4)

2012

  • + December (2)
  • + November (1)
  • + October (14)
  • + September (19)
bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    Loading Comments...

    You must be logged in to post a comment.