
volatility
@volatility
Official account of the Volatility Memory Analysis Project and Windows Malware and Memory Forensics Training. volatilityfoundation.org
ID: 15709883
http://github.com/volatilityfoundation 03-08-2008 12:02:59
3,3K Tweet
21,21K Followers
11 Following

.volatility #PluginContest #Contender Shusei Tomonaga: ETW Scan is an investigative tool to aid security researchers, reverse engineers & incident responders in leveraging Windows Event Tracing for Windows (ETW) data for enhanced threat hunting & analysis. #DFIR #memoryforensics

.volatility #PluginContest #Contender Thomas Clarke: Image Extraction, NSRL Filtering & Image Classifiers plugins help investigators extract memory-resident images & sort those images using numerous classifiers. #DFIR #memoryforensics

.volatility #PluginContest #Contender Kartik N. Iyer + Parag H. Rughani: Thread Local Storage (TLS) Callback is a feature-rich plugin designed to detect, analyze & disassemble TLS callbacks in memory samples. #DFIR #memoryforensics

.volatility #PluginContest #Contender Valentin Obst: btf2json focuses on large-scale Linux memory analysis, incorporating information in the vmlinuz file to create #Volatility3 symbol tables without the need for a full debug kernel. #DFIR #memoryforensics

.volatility #PluginContest #Contender Sylvain Peyrefitte: ScringsScan + VadScringsScan provide syntax-aware scanning for 6 languages in kernel memory in Linux, macOS & Windows + in-process VADs in Windows, improving in-memory script payloads searching. #DFIR #memoryforensics

We will announce the volatility #PluginContest winners tomorrow, Friday, March 28, so stay tuned! #DFIR #memoryforensics #Volatility3


We had some awesome submissions to the volatility #PluginContest. The first place submission is a HUGE contribution to #memoryforensics on the Linux side, and solves a hard problem that others have grappled with for some time! #DFIR








Our highly popular and technical training, "Malware and Memory Forensics with Volatility", has been fully converted to volatility 3 and significantly updated, including many new sections and 8 new, in-depth labs. Available online and in VA in October. memoryanalysis.net/courses-malwarโฆ