Digital forensics and incident response (DFIR) analysts constantly face the challenge of quickly acquiring and extracting value from raw digital evidence. Investigators must make sense of unfiltered accounts of all attacker activities recorded during incidents. They need to analyze attacker activities against data at rest, data in motion, and data in use. And they must accomplish all this while operating within resource constraints. That’s why DFIR analysts should have Volatility open-source software (OSS) in their toolkits.
Volatility is a command-line tool that lets DFIR teams acquire and analyze the volatile data that is temporarily stored in random access memory (RAM). Such data often contains critical clues for investigators. Volatility’s extraction techniques are performed completely independent of the system being investigated, yet still offer visibility into the runtime state of the system. What’s more, Volatility’s source code is freely available for inspection, modifying, and enhancement—and that brings organizations financial advantages along with improved security.