
Ein fortschrittliches Framework für Speicherforensik
Dieses Projekt ist archiviert. Siehe Volatility 3 für moderne Untersuchungen: https://github.com/volatilityfoundation/volatility3
Das Volatility Framework ist eine vollständig quelloffene Sammlung von Werkzeugen, implementiert in Python unter der GNU General Public License, zur Extraktion digitaler Artefakte aus flüchtigen Arbeitsspeicher-Proben (RAM). Die Extraktionstechniken arbeiten völlig unabhängig vom untersuchten System, bieten jedoch Einblick in den Laufzeitzustand des Systems. Das Framework soll Menschen mit den Techniken und Komplexitäten vertraut machen, die mit der Extraktion digitaler Artefakte aus flüchtigen Speicherproben verbunden sind, und eine Plattform für weitere Arbeiten in diesem spannenden Forschungsbereich bieten.
Die Volatility-Distribution ist erhältlich unter: http://www.volatilityfoundation.org/#!releases/component_71401
Volatility sollte auf jeder Plattform laufen, die Python (http://www.python.org) unterstützt.
Volatility unterstützt Untersuchungen der folgenden Speicherabbilder:
Windows:
Hinweis: Bitte beachten Sie die Richtlinien unter folgendem Link für Hinweise zur Kompatibilität mit kürzlich gepatchten Windows 7 (oder neuer) Speicherproben:
https://github.com/volatilityfoundation/volatility/wiki/2.6-Win-Profiles
Linux:
Mac OSX:
Volatility bietet keine Funktionen zur Erfassung von Speicherproben. Für die Erfassung stehen sowohl kostenlose als auch kommerzielle Lösungen zur Verfügung. Wenn Sie Vorschläge zu geeigneten Erfassungslösungen wünschen, kontaktieren Sie uns bitte unter:
volatility (at) volatilityfoundation (dot) org
Volatility unterstützt eine Vielzahl von Proben-Dateiformaten und die Möglichkeit, zwischen diesen Formaten zu konvertieren:
Eine detailliertere Liste der Funktionen finden Sie unter:
https://github.com/volatilityfoundation/volatility/wiki
Siehe auch das Community-Plugins-Repository:
https://github.com/volatilityfoundation/community
Wenn Sie Volatility ausprobieren möchten, können Sie exemplarische Speicherabbilder von folgender URL herunterladen:
https://github.com/volatilityfoundation/volatility/wiki/Memory-Samples
Mailinglisten zur Unterstützung der Benutzer und Entwickler von Volatility finden Sie unter folgender Adresse:
http://lists.volatilesystems.com/mailman/listinfo
Für Informationen oder Anfragen wenden Sie sich an:
Volatility Foundation
Web: http://www.volatilityfoundation.org http://volatility-labs.blogspot.com http://volatility.tumblr.com
Email: volatility (at) volatilityfoundation (dot) org
IRC: #volatility auf freenode
Twitter: @volatility
Einige Plugins können weitere Anforderungen haben, die unter folgendem Link zu finden sind: https://github.com/volatilityfoundation/volatility/wiki/Installation
Entpacken Sie die neueste Version von Volatility von volatilityfoundation.org
Um die verfügbaren Optionen zu sehen, führen Sie "python vol.py -h" oder "python vol.py --info" aus.
Beispiel:
$ python vol.py --info Volatility Foundation Volatility Framework 2.6
AMD64PagedMemory - Standard AMD 64-bit address space. ArmAddressSpace - Address space for ARM processors FileAddressSpace - This is a direct file AS. HPAKAddressSpace - This AS supports the HPAK format IA32PagedMemory - Standard IA-32 paging address space. IA32PagedMemoryPae - This class implements the IA-32 PAE paging address space. It is responsible LimeAddressSpace - Address space for Lime LinuxAMD64PagedMemory - Linux-specific AMD 64-bit address space. MachOAddressSpace - Address space for mach-o files to support atc-ny memory reader OSXPmemELF - This AS supports VirtualBox ELF64 coredump format QemuCoreDumpElf - This AS supports Qemu ELF32 and ELF64 coredump format VMWareAddressSpace - This AS supports VMware snapshot (VMSS) and saved state (VMSS) files VMWareMetaAddressSpace - This AS supports the VMEM format with VMSN/VMSS metadata VirtualBoxCoreDumpElf64 - This AS supports VirtualBox ELF64 coredump format Win10AMD64PagedMemory - Windows 10-specific AMD 64-bit address space. WindowsAMD64PagedMemory - Windows-specific AMD 64-bit address space. WindowsCrashDumpSpace32 - This AS supports windows Crash Dump format WindowsCrashDumpSpace64 - This AS supports windows Crash Dump format WindowsCrashDumpSpace64BitMap - This AS supports Windows BitMap Crash Dump format WindowsHiberFileSpace32 - This is a hibernate address space for windows hibernation files.