Using Volatility in Kali Linux
To start the Volatility Framework, click on the All Applications
button at the bottom of the sidebar and type volatility
in the search bar:
data:image/s3,"s3://crabby-images/79661/7966150754820acee45f286e59e6d5b9bdace016" alt=""
Clicking on the volatility
icon starts the program in a Terminal. When Volatility starts, we see that the version being used is 2.6
and also presents us with options for use:
data:image/s3,"s3://crabby-images/3cc6b/3cc6ba3b56b75e1955341208a8dcb073342e7954" alt=""
For a complete list of all plugins at your fingertips, open a separate Terminal and run the volatility -h
command, rather than having to scroll to the top of the Terminal that you are using to run Volatility plugin commands:
data:image/s3,"s3://crabby-images/64ed3/64ed3bd3c019b4c2eb0eb387c95ce8217a4f7bc2" alt=""
The following screenshot shows a snippet of some of the many plugins within the Volatility Framework:
data:image/s3,"s3://crabby-images/4fe1d/4fe1d28232392cf46be050cd82e6255b0e38dcce" alt=""
This list comes in handy when performing analysis as each plugin comes with its own short description. The following screenshot shows a snippet of the help
command, which gives a description of the imageinfo
plugin:
data:image/s3,"s3://crabby-images/d20a3/d20a39f1078b3fe2630f4c2f1b65ad549ae3dee3" alt=""
The format for using plugins in Volatility is:
volatility -f [filename] [plugin] [options]
As seen in the previous section...