
Volatility
Volatility is an open-source memory forensics framework for extracting digital artefacts from RAM dumps during incident response and malware analysis.
0 upvotes · 0 downvotes
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
What it is
Volatility (now primarily Volatility 3) is an open-source memory forensics framework maintained with support from the Volatility Foundation. Analysts use it to examine RAM captures from Windows, Linux, macOS and other profiles, recovering processes, network connections, injected code and other volatile artefacts that disk forensics may miss.
What it helps with
- Analysing memory dumps from incident response and malware investigations.
- Listing processes, modules, network artefacts and registry or file-related structures via plugins.
- Supporting modern Volatility 3 workflows after Volatility 2 deprecation.
- Extending analysis with community and custom plugins under documented APIs.
- Teaching and practising memory forensics in labs and academic settings.
- Pairing with acquisition tools that produce compatible memory images.
Who it's for
Incident responders, malware analysts, digital forensics examiners and students who need to inspect volatile memory from systems they are authorised to investigate.
Worth knowing
Use Volatility only on memory images you are permitted to analyse. Volatility 3 is the actively developed line; Volatility 2 is deprecated. Licensing is documented by the Volatility Foundation (including the Volatility Software License for Volatility 3). Official home pages are volatilityfoundation.org and the volatilityfoundation/volatility3 repository. Attribution: framing from the Volatility Foundation site and Volatility 3 README.