pip with the Python installer
Recommendedpippy -3 -m pip install volatility3
Memory forensics framework for RAM images
Volatility 3 parses captured memory images so you can list processes, handles, network sockets, loaded modules and mapped files — the state that never reached the disk. It is a framework: reader plugins run over an image with a symbol table that matches the OS build.
Memory images contain everything running at capture time, including credentials and personal data of other users. Handle them under the evidence and retention rules that apply to your organisation.
Supported platforms
5
Documented install or usage guidance
Learning curve
advanced
Difficulty of becoming productive, not of the underlying theory
Tags
memory, ir, processes, rootkit, artefacts
Dataset entry
volatility3.ts
Reviewed 2026-01-03
Grouped by platform. Elevation requirements are marked per method.
py -3 -m pip install volatility3
python3 -m venv .venv && source .venv/bin/activate
pip install volatility3
vol -h
Needs elevated privileges (sudo / Administrator).
sudo apt install volatility3
Package availability follows your distribution and enabled repositories. Entry revised 3 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Reads the KDBG/kernel signature to establish OS and build, which determines the symbol table you need.
vol -f lab-2026-01-03.raw windows.info
Notes
Shows the process tree with creation times, the first pass of any triage.
vol -f lab.raw windows.pslist --columns PID PPID Name CreateTime
Lists sockets with owning processes — how you connect 'who called out' to 'which binary did it'.
vol -f lab.raw windows.netscan
Reports regions marked execute/read/write that are not backed by a mapped image. A hypothesis generator, nothing more.
vol -f lab.raw windows.malfind
Notes
Linux readers require a symbol table for the exact kernel build.
vol -f mem.lime linux_pslist.PsList && vol -f mem.lime linux_lsmod
Notes
JSON rendering feeds a notebook or a timeline builder.
vol -f lab.raw -r json windows.pslist > pslist.json
Establish what was running and connected at capture time.
Observe process and memory behaviour in an isolated lab.
Confirm a service that left no disk artefact did run.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Obtain or generate the matching table (Windows: PDB via a symbol cache; Linux: build with `dwarftools`/`volatility3/framework/symbols/` workflow) and pass `--symbol-tables /path`.
Possible causes
Usual fix
List what your build provides: `vol -h` and `vol --list-plugins`. v3 names are namespaced (`windows.pslist`).
Possible causes
Usual fix
Verify size and hash against the acquisition record; decompress explicitly first (`7z e`, `avml-decompress`).
Not documented yet: winpmem, avml, rekal. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.