VolUtility Logo

VolUtility

0
Free
Visit Website

VolUtility is a web interface for the Volatility Memory Analysis framework that runs plugins, stores output in a mongo database, extracts files, enables search across plugins and file content, and supports working on multiple images in one database. It also provides a video demo of its features and detailed installation and usage instructions in the wiki.

FEATURES

ALTERNATIVES

A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.

A powerful tool for analyzing and visualizing system activity timelines.

A library to access and parse Windows Shortcut File (LNK) format.

Open source digital forensics tools for analyzing disk images and recovering files.

Modern digital forensics and incident response platform with comprehensive tools.

IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.

libevt is a library to access and parse Windows Event Log (EVT) files.

Online platform for image steganography analysis