• GitHub
  • Contact
The Volatility Foundation - Promoting Accessible Memory Analysis Tools Within the Memory Forensics Community
  • The Volatility Framework
  • Training
  • Events
  • FAQ
  • Contest
  • About
  • Blog
Select Page

Acquiring Memor(ies) from 2014

by Volatility | Dec 31, 2014 | arsenal, artofmemoryforensics, blackhat, contest, forensics, knttools, omfw, training, truecrypt, volatility, volatility foundation

2014 is extremely volatile. Any minute now, it will be gone. Thus, we wanted to take a minute and preserve some of the more exciting memories. Specifically, we wanted to summarize how the memory forensics field and Volatility community has progressed this year....

The Secret to 64-bit Windows 8 and 2012 Raw Memory Dump Forensics

by Volatility | Jan 13, 2014 | forensics, kernel, omfw, training, volatility, win8, windows

Those of you who attended OMFW 2013 received a talk on Windows 8 and Server 2012 memory forensics with Volatility. One of the interesting aspects of this new operating system, which includes 8.1 and 2012 R2, is that the kernel debugger data block...

What’s Happening in the World of Volatility?

by Volatility | May 13, 2013 | contest, forensics, malware, movp, omfw, training, volatility

Volatility is not just an advanced open-source memory forensics framework for Windows, Linux, Mac, and Android. Its a community, an attitude, a lifestyle, and every day it grows in popularity, maturity, and integrity. This post will summarize some of the upcoming...

OMFW 2012: Mining the PFN Database for Malware Artifacts

by Volatility | Oct 19, 2012 | forensics, kernel, knttools, malware, omfw, windows

There are few people in the world who know more about physical memory acquisition and analysis than Mr. Garner; President of GMG Systems, Inc. and author of ( X http://www.gmgsystemsinc.com/knttools/) KnTTools. At a rare conference appearance, George discussed how he...

OMFW 2012: The Analysis of Process Token Privileges

by Volatility | Oct 19, 2012 | malware, omfw, volatility, windows

Reverse engineering windows systems nowadays involves looking at static data, such as executables, symbols, pdbs, and/or dynamic data when debugging with a tool like windbg. Determining data structures and the meaning of their content has proven to be time consuming,...

MoVP for Volatility 2.2 and OMFW 2012 Wrap-Up

by Volatility | Oct 12, 2012 | forensics, linux, movp, omfw, volatility, windows

The Month of Volatility Plugins and Open Memory Forensics Workshop 2012 have now come to an end. Volatility 2.2 has been released. We hope you enjoyed spending time with us learning about the new features and innovative research that’s being built into the...
« Older Entries

Volatility Blog Archive

2025

  • + July (1)
  • + May (2)
  • + March (1)

2024

  • + August (1)
  • + July (1)
  • + March (1)

2023

  • + August (1)
  • + July (1)
  • + June (1)
  • + March (1)
  • + February (1)
  • + January (1)

2022

  • + July (1)
  • + February (1)
  • + January (1)

2021

  • + October (1)
  • + August (1)
  • + May (1)
  • + January (1)

2020

  • + November (1)
  • + May (2)

2019

  • + November (1)
  • + October (2)
  • + July (1)
  • + June (1)

2018

  • + November (2)
  • + May (1)
  • + February (1)

2017

  • + November (1)
  • + June (1)
  • + April (1)

2016

  • + December (2)
  • + September (1)
  • + August (2)
  • + July (1)
  • + April (3)

2015

  • + November (2)
  • + October (1)
  • + August (2)
  • + July (2)
  • + June (1)
  • + May (1)
  • + March (1)
  • + February (1)
  • + January (1)

2014

  • + December (1)
  • + October (3)
  • + September (5)
  • + August (6)
  • + July (2)
  • + May (1)
  • + April (2)
  • + February (2)
  • + January (5)

2013

  • + October (3)
  • + September (2)
  • + August (1)
  • + June (9)
  • + May (15)
  • + April (2)
  • + March (2)
  • + February (1)
  • + January (4)

2012

  • + December (2)
  • + November (1)
  • + October (14)
  • + September (19)
bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo
    bluesky logo

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    All Content © The Volatility Foundation, a 501(c)(3) Nonprofit Organization.

    SOCIALICON
    SOCIALICON
    SOCIALICON
    SOCIALICON
    SOCIALICON
     

    Loading Comments...
     

    You must be logged in to post a comment.