You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
memoryforensics1 edited this page Apr 5, 2020
·
2 revisions
Welcome to the VolExp wiki!
This program allows you access to a Memory Dump.
It can also function as a plugin to the Volatility Framework (https://github.com/volatilityfoundation/volatility).
This program functions similarly to Process Explorer/Hacker, but additionally it allows the user access to a Memory Dump (or access the real-time memory on the computer using Memtriage).
This program can run from Windows, Linux and MacOS machines, but can only use Windows memory images.
Quick Start
Download the volexp.py file (download the memtriage.py file as well and replace it with your memtriage.py file if you want to use memtriage https://github.com/gleeda/memtriage).
Run as a standalone program or as a plugin to Volatility: