git:20260518.471df3d to git:20260710.2925510

16 added, 21 removed. Audit A to B.

---
- name: "Analyze memory images for processes, modules, and malware indicators with Volatility 3"
- slug: "analyze-memory-images-for-processes-modules-and-malware-indicators-with-volatility-3"
+ title: "Analyze memory images for processes, modules, and malware indicators with Volatility 3"
description: "Inspect captured RAM images to enumerate processes, modules, handles, and suspicious in-memory behavior before escalation or evidence handoff."
- github_stars: 4062
- verification: "listed"
+ verification: "security_reviewed"
source: "https://github.com/volatilityfoundation/volatility3"
author: "volatilityfoundation"
publisher_type: "organization"
- category: "Runbooks & Diagnostics"
- framework: "Multi-Framework"
+ category:
+ - "Runbooks & Diagnostics"
+ framework:
+ - "Multi-Framework"
tool_ecosystem:
github_repo: "volatilityfoundation/volatility3"
github_stars: 4062
---
# Analyze memory images for processes, modules, and malware indicators with Volatility 3
Inspect captured RAM images to enumerate processes, modules, handles, and suspicious in-memory behavior before escalation or evidence handoff.
## Prerequisites
Volatility 3 CLI, Python 3.8+ environment, supported memory image file, optional symbol packs depending on target OS
## Installation
- Use the upstream install or setup path that matches your environment:
- - pip install --user -e ".[full]"
- - pip install volatility3
- - git clone https://github.com/volatilityfoundation/volatility3.git
- - pip install -e ".[dev]"
+ Choose whichever fits your setup:
- Requirements and caveats from upstream:
- - Some also require/accept other options. Run vol <plugin> -h for more information on a particular command.
- - Volatility 3 requires Python 3.8.0 or later and is published on the [PyPi registry](https://pypi.org/project/volatility3).
- - Important: The first run of volatility with new symbol files will require the cache to be updated. The symbol packs contain a large number of symbol files and so may take some time to update!
+ 1. Copy this skill folder into your local skills directory.
+ 2. Clone the repo and symlink or copy the skill into your agent workspace.
+ 3. Add the repo as a git submodule if you manage shared skills centrally.
+ 4. Install it through your internal provisioning or packaging workflow.
+ 5. Download the folder directly from GitHub and place it in your skills collection.
- Basic usage or getting-started notes:
- - Install the required dependencies:
- - shell
- - See available options:
+ Install command or upstream instructions:
- - Source: https://github.com/volatilityfoundation/volatility3
- - Extracted from upstream docs: https://raw.githubusercontent.com/volatilityfoundation/volatility3/HEAD/README.md
+ ```
+ Install Volatility 3 from PyPI or the upstream repository, make the vol command available in the agent environment, then point it at a captured memory image and run the needed plugins for triage.
+ ```
## Documentation
- https://volatility3.readthedocs.io/en/latest/
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/analyze-memory-images-for-processes-modules-and-malware-indicators-with-volatility-3/)