Analyze memory images for processes, modules, and malware indicators with Volatility 3
Inspect captured RAM images to enumerate processes, modules, handles, and suspicious in-memory behavior before escalation or evidence handoff.
Prerequisites
Volatility 3 CLI, Python 3.8+ environment, supported memory image file, optional symbol packs depending on target OS
Installation
Choose whichever fits your setup:
- Copy this skill folder into your local skills directory.
- Clone the repo and symlink or copy the skill into your agent workspace.
- Add the repo as a git submodule if you manage shared skills centrally.
- Install it through your internal provisioning or packaging workflow.
- Download the folder directly from GitHub and place it in your skills collection.
Install command or upstream instructions:
Install Volatility 3 from PyPI or the upstream repository, make the vol command available in the agent environment, then point it at a captured memory image and run the needed plugins for triage.