Official account of the Volatility Memory Analysis Project and Windows Malware and Memory Forensics Training. volatilityfoundation.org

Joined August 2008
187 Photos and videos
.@volatility New Release: #volatility3 v2.28.0 - visit github.com/volatilityfoundat… for details and downloads. #memoryforensics #dfir
36
111
8,729
volatility retweeted
I am excited to announce that I will be speaking at @bsidesnash on May 15th. Be sure to attend to see all the latest @volatility 3 plugins against the most sophisticated and devastating malware from the wild!
1
8
16
2,693
volatility retweeted
Memory-only malware leaves no trace on the file system & is commonly used by threat actors ranging from criminal organizations to ransomware operators to APTs. In our @volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-m…
34
139
11,020
We have announced the winners of the 2025 @volatility #PluginContest! And the First Place is: Daniel Baier for XFRM Inspector Read the full Contest Results in our blog post: volatilityfoundation.org/the… Congrats to all winners & thank you to all participants! #DFIR #memoryforensics
The 2025 @volatility #PluginContest review is complete! We received 8 submissions from 7 different countries that included 20 plugins! We will be highlighting each #Contender & the winners will be announced on Friday! #DFIR #memoryforensics
6
11
3,573
We are excited to announce the 2025 @volatility #PluginContest First Place winner is: Daniel Baier for XRFM Inspector See the full Contest Results: volatilityfoundation.org/the… Congrats to all winners & thank you to all participants! #DFIR #memoryforensics
The 2025 @volatility #PluginContest review is complete! We received 8 submissions from 7 different countries that included 20 plugins! We will be highlighting each #Contender & the winners will be announced on Friday! #DFIR #memoryforensics
1
7
11
3,473
The annual @volatility #PluginContest continues to highlight how #memoryforensics researchers are innovating contributing to #Volatility3! Special thanks to the core developers & previous winners who helped review this year's submissions!
1
4
487
We will announce the winners of the 2025 @volatility #PluginContest winners tomorrow, Friday, Mar 6, so stay tuned! #DFIR #memoryforensics #Volatility3
The 2025 @volatility #PluginContest review is complete! We received 8 submissions from 7 different countries that included 20 plugins! We will be highlighting each #Contender & the winners will be announced on Friday! #DFIR #memoryforensics
4
4
2,791
The 2025 @volatility #PluginContest review is complete! We received 8 submissions from 7 different countries that included 20 plugins! We will be highlighting each #Contender & the winners will be announced on Friday! #DFIR #memoryforensics
9
7
13
13,047
.@volatility #PluginContest #Contender Théo Letailleur: Journald Extractor automates extraction of Linux journal files cached in memory, along with analysis via the open-source go-journalctl tool to obtain parsed versions of these files from memory. #DFIR #memoryforensics
2
1
609
.@volatility #PluginContest #Contender Kyrre Wahl Kongsgård: Arrow & Parquet Renderers allows #Volatility3 plugin output to be written via the Arrow Parquet renderers, enabling the output to be integrated into tools for modern data analysis workflows. #DFIR #memoryforensics
2
1
502
.@volatility #PluginContest #Contender Diyar Saadi Ali: This submission includes a suite of detection plugins & tools to identify suspicious processes artifacts within the memory sample of a suspected system using a variety of heuristics & indicators. #DFIR #memoryforensics
2
1
455
.@volatility #PluginContest #Contender Kartik Iyer: APCWatch & MalAPC together provide the capability to identify & analyze APC injection attacks in Windows memory forensics, one of the most sophisticated code injection techniques employed by modern malware #DFIR #memoryforensics
3
1
491
.@volatility #PluginContest #Contender Thomas Clark: The EA App Artifacts, MetaHorizonWorlds & SteamArtifacts plugins help investigators with incidents involving popular gaming platforms by scanning memory for relevant processes and artifacts. #DFIR #memoryforensics
2
2
558
.@volatility #PluginContest #Contender Daniel Baier: XRFM Inspector includes a suite of #Volatility3 plugins that perform the extraction of VPN (IPSEC) related artifacts and cryptographic keys from the XFRM Linux subsystem. #DFIR #memoryforensics
2
1
482
.@volatility #PluginContest #Contender Jan-Hendrik Lang: MemoryInvestigator specializes in Windows memory analysis & integrates #Volatility3 and LLMs, including Retrieval-Augmented Generation (RAG) and an enhanced Tree-of-Table Algorithm #DFIR #memoryforensics
2
3
476
.@volatility #PluginContest #Contender Devarjya Purkayastha: PEScan provides an alternative method for analyzing PE files in a memory sample, assigning a threat score to each memory region that contains a PE file & summarizing high/critical regions. #DFIR #memoryforensics
2
2
545
.@volatility New Release: #volatility3 v2.27.0 - visit github.com/volatilityfoundat… for details and downloads. #memoryforensics #dfir
41
134
9,063
volatility retweeted
We’ve now made our @DEATHCon2025 workshop Building Custom Memory Analysis Tools with the Modern Python Data Ecosystem publicly available. The workshop shows how to build custom memory forensics tools on top of @volatility output using @marimo_io, @duckdb, and @IbisData. We start with an introduction to marimo notebooks, DuckDB, and the Ibis dataframe library, then move into incident response workflows where Volatility plugin output is treated as tabular data stored in DuckDB tables and processed and presented interactively in a notebook environment. From there, we build reusable analysis components, show how marimo’s reactive execution model enables a custom interactive environment for YARA development, demonstrate how to process string data contained in memory dumps, and finally show how to create custom interactive visualizations and widgets. All notebooks, files, and accompanying videos are now available to everyone.
1
5
4
1,649
And that’s it! The 2025 @volatility #PluginContest is now closed. Stay tuned for winner announcements in the coming weeks! And good luck to all contenders! #memoryforensics #opensource #dfir
31 Dec 2025
Today is the last day to submit entries to the #PluginContest! This is your chance to gain industry-wide visibility for your work, contribute to an important open-source project, and compete for cash prizes! More details below!👇
2
3
1,834