Skip to content

Volatility 3

Memory forensics framework for RAM images

VerifiedForensics· Memory AnalysisAdvancedBSD-2-ClauseOpen sourceEntry revised 3 Jan 2026
  • Linux
  • macOS
  • Windows
  • Source
  • Docker

Overview

6 commands documented

Volatility 3 parses captured memory images so you can list processes, handles, network sockets, loaded modules and mapped files — the state that never reached the disk. It is a framework: reader plugins run over an image with a symbol table that matches the OS build.

Memory images contain everything running at capture time, including credentials and personal data of other users. Handle them under the evidence and retention rules that apply to your organisation.

Supported platforms

5

Documented install or usage guidance

Learning curve

advanced

Difficulty of becoming productive, not of the underlying theory

Tags

memory, ir, processes, rootkit, artefacts

Dataset entry

volatility3.ts

Reviewed 2026-01-03

Installation

Grouped by platform. Elevation requirements are marked per method.

pip with the Python installer

Recommendedpip
py -3 -m pip install volatility3

Package availability follows your distribution and enabled repositories. Entry revised 3 Jan 2026 — confirm the current release on the project's own download page.

Commands

6 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Identify the image before anything else

bash

Reads the KDBG/kernel signature to establish OS and build, which determines the symbol table you need.

vol -f lab-2026-01-03.raw windows.info

Notes

  • Without a matching symbol table most plugins return nothing; supply one with `--symbol-tables` or the ISO directory.

02List processes

bash

Shows the process tree with creation times, the first pass of any triage.

vol -f lab.raw windows.pslist --columns PID PPID Name CreateTime

03Reconstruct network state

bash

Lists sockets with owning processes — how you connect 'who called out' to 'which binary did it'.

vol -f lab.raw windows.netscan

04Look for injected or private executable memory

bash

Reports regions marked execute/read/write that are not backed by a mapped image. A hypothesis generator, nothing more.

vol -f lab.raw windows.malfind

Notes

  • Legitimate JIT runtimes (JVMs, .NET, browsers) produce similar patterns. Always correlate with process lineage.

05Linux images

bash

Linux readers require a symbol table for the exact kernel build.

vol -f mem.lime linux_pslist.PsList && vol -f mem.lime linux_lsmod

Notes

  • Acquire with LiME on a live system; record the `uname -a` output alongside the image or the symbols will not match later.

06Machine-readable results

bash

JSON rendering feeds a notebook or a timeline builder.

vol -f lab.raw -r json windows.pslist > pslist.json

What it is used for

  • Incident triage

    Establish what was running and connected at capture time.

  • Malware coursework

    Observe process and memory behaviour in an isolated lab.

  • Disk-image cross-checking

    Confirm a service that left no disk artefact did run.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

SymbolTableError / 'No suitable symbol servers found'Cause 1/3

Possible causes

  • No symbol table for the image's exact OS build.

Usual fix

Obtain or generate the matching table (Windows: PDB via a symbol cache; Linux: build with `dwarftools`/`volatility3/framework/symbols/` workflow) and pass `--symbol-tables /path`.

Plugin names from a tutorial do not existCause 2/3

Possible causes

  • Volatility 2 syntax (`volatility pslist -f`, `linux_...` module naming) differs from v3.

Usual fix

List what your build provides: `vol -h` and `vol --list-plugins`. v3 names are namespaced (`windows.pslist`).

Crash / 'Invalid memory image'Cause 3/3

Possible causes

  • Truncated capture, compressed image passed raw, or a hibernation file mistaken for a RAM dump.

Usual fix

Verify size and hash against the acquisition record; decompress explicitly first (`7z e`, `avml-decompress`).

Tips

  • Hash the image (SHA-256) before analysis and again after; note both in the case file.
  • Capture `windows.cmdline` and `windows.registry.userassist` early — they answer intent questions quickly.
  • Work on a copy in a VM with no network access to the image's origin.

Alternatives & comparisons

Not documented yet: winpmem, avml, rekal. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Forensics