volatility
An advanced memory forensics framework (by volatilityfoundation)
fibratus
Adversary tradecraft detection, protection, and hunting (by rabbitstack)
volatility | fibratus | |
---|---|---|
19 | 46 | |
7,718 | 2,351 | |
- | 0.4% | |
0.0 | 9.4 | |
2 months ago | 4 days ago | |
Python | Go | |
GNU General Public License v3.0 only | GNU General Public License v3.0 or later |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
volatility
Posts with mentions or reviews of volatility.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-05-28.
-
๐ Insomni'hack 2025 CTF write-up
We were given a quite big 20250312.mem file. Looking at the name of the challenge and the size of the file, it was clear it was required to use volatility.
-
What is the appropriate uncompressed kernel ELF to use with dwarf2json? [ 5.19.0-42-generic #43~22.04.1-Ubuntu ], in order to create generate a custom symbols table to conduct linux memory forensics on Ubuntu 22.04?
I need this to create generate a custom symbols table (using dwarf2json), in order to run a memory dump acquired by Ubuntu 22.04, as Ubuntu 22.04 kernel does not work anymore with volatility 2 (Issue here: volatilityfoundation/volatility#828)
-
volatility memory analysis ep.8 โ linux/mac Q!
Take a look at this link and specifically note how the profiles are named, especially Ubuntu - https://github.com/volatilityfoundation/volatility/wiki/Linux-Command-Reference
-
Dump file without a extension
I think the typical tool for analyzing OS memory dumps is Volatility but I can't give you a course in how to use it, that is supposedly what your school should be doing.
- memory dump with FTK Imager
-
How to inspect a Linux machine
Analyzing memory dumps can be hard, especially at the beginning. You might want to use comprehensive Frameworks like volatility.
-
Does anyone know why volatility isnt working?
git clone https://github.com/volatilityfoundation/volatility.git whenever i want to run something I get PS C:\Users\czare_000\python-course-for-beginners\bs4\volatility> & C:/Users/czare_000/AppData/Local/Programs/Python/Python310/python.exe c:/Users/czare_000/python-course-for-beginners/bs4/volatility/volatility/debug.py Traceback (most recent call last): File "c:\Users\czare_000\python-course-for-beginners\bs4\volatility\volatility\debug.py", line 27, in import volatility.conf ModuleNotFoundError: No module named 'volatility' or i also get except Exception, e: ^^^^^^^^^^^^ SyntaxError: multiple exception types must be parenthesized
-
Analyzing raw image
Volatility is python based so you will need to install it and volatility's required dependencies. You can find the install instructions here https://github.com/volatilityfoundation/volatility
-
PChunter equivalent on Linux?
volatility - Version 2 Version 3
- How do you work on memory analysis nowadays? Discussion about the Volatility status.
fibratus
Posts with mentions or reviews of fibratus.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-01-05.
- Announcing Fibratus 2.0.0
-
Announcing Fibratus 1.10.0 - a modern Windows kernel tracing and threat detection engine
I'm thrilled to announce the availability of Fibratus 1.10.0. This release brings a set of interesting features , such as the Yara function for combining signature and behavior-based detections, expanded detection rules catalog, native grammar for sequence rules, etc.
-
Fibratus 1.10.0 - a modern Windows kernel tracing and threat detection engine built in Go
I'm happy to announce the availability of Fibratus 1.10.0. Fibratus aims at providing a high-performance engine for capturing Windows system events and asserting them against a ruleset for the purpose of detecting adversary kill chain. All rules are built on top of the prominent MITRE security framework.
- Release v1.10.0 ยท Fibratus
- Announcing fibratus 1.10.0 - a modern Windows kernel tracing and threat detection engine
- Announcing Fibratus 1.8.0 - a modern tool for Windows kernel tracing with a focus on security
-
Fibratus - a modern tool for Windows kernel tracing with a focus on threat detection and prevention
You can check the full changelog here.
- Fibratus: Open-source threat detection and prevention solution
What are some alternatives?
When comparing volatility and fibratus you can also consider the following projects:
one_gadget - The best tool for finding one gadget RCE in libc.so.6
attack-stix-data - STIX data representing MITRE ATT&CK
MalConfScan - Volatility plugin for extracts configuration data of known malware
space-cloud - Open source Firebase + Heroku to develop, scale and secure serverless apps on Kubernetes
picoCTF - The platform used to run picoCTF 2019.
core - Backend server API handling user mgmt, database, storage and real-time component