The volatility framework, or the volatile memory extraction utility framework, is an open collection of tools that have been implemented in Python. The framework is open source. It supports Microsoft Windows, macOS X, and Linux.
Volatility supports the investigation of the following memory images:
- Windows:
- 32-bit Windows XP (Service Packs 2 and 3)
- 32-bit Windows 2003 Server (Service Packs 0, 1, and 2)
- 32-bit Windows Vista (Service Packs 0, 1, and 2)
- 32-bit Windows 2008 Server (Service Packs 1 and 2)
- 32-bit Windows 7 (Service Packs 0 and 1)
- 32-bit Windows 8, 8.1, and 8.1 Update 1
- 32-bit Windows 10 (initial support)
- 64-bit Windows XP (Service Packs 1 and 2)
- 64-bit Windows 2003 Server (Service Packs 1 and 2)
- 64-bit Windows Vista (Service Packs 0, 1, and 2)
- 64-bit Windows 2008 Server (Service Packs 1 and 2)
- 64-bit Windows 2008 R2 Server (Service Packs...