$npx skillfedfor your agent

volatility3

Memory forensics framework

With conditionsPyPI SecurityReleased Apr 202674.6K downloads / moVSLPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — volatility3-2.28.0-py3-none-any.whl
v2.28.0 · released 2026-04-30 · Python >=3.8.0 · 1 runtime deps: pefile

Yes, if you work in digital forensics or incident response. Volatility 3 is the industry-standard memory analysis framework with active maintenance, low install friction, and no known vulnerabilities. The custom VSL license requires review for your use case, but the framework itself is stable and widely adopted. Install it if you need to analyze memory dumps; skip it if you have no forensic analysis requirements.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8.0 or later.
  • Symbol table packs for Windows, macOS, and Linux must be downloaded separately and placed in the volatility3/symbols directory; first run with new symbol files requires cache initialization which may take time.
  • Low install friction with a single runtime dependency (pefile).

License · maintenance · safety

VSL (unclear) — Licensed under the Volatility Software License (VSL), which is a custom license distinct from common open-source licenses. The license treatment is marked unclear, so you should review the full VSL v1.0 at https://www.volatilityfoundation.org/license/vsl-v1.0 before using in commercial or redistributed contexts.

last release 2026-04-30 (106 days) · last repo commit 2026-08-14 · 4,326 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 74,631 downloads/mo, #14,809 on PyPI

Verify before relying

pip install volatility3

from volatility3.cli import main

# Run a plugin on a memory sample
vol -f /path/to/memory.vmem windows.info
  • Whether the VSL license permits commercial use or redistribution without additional restrictions beyond what is stated in the license text.
  • Performance characteristics and memory overhead when analyzing large memory samples.
  • Compatibility with memory dumps from systems other than Windows, macOS, and Linux.
Same gist for agents: .md · .json

What it is and what it does

Volatility 3 is a complete rewrite of the original Volatility framework, designed to extract and analyze digital artifacts directly from volatile memory (RAM) samples. It operates independently of the target system's operating system, providing visibility into the runtime state without requiring the system to be running. The framework supports Windows, Linux, and macOS memory analysis through a plugin architecture accessible via the command-line `vol` tool.

The package requires Python 3.8.0 or later and depends only on pefile for its core functionality. Symbol tables—which map memory addresses to kernel symbols—must be obtained separately for each supported OS and placed in the symbols directory. Windows symbols can be automatically queried and cached, but macOS and Linux symbols require manual generation using tools like dwarf2json. The framework is intended both for forensic investigation and as a platform for research into memory artifact extraction techniques.

Use it for

  • Analyze Windows memory dumps to identify running processes, network connections, and malware artifacts in incident response.
  • Extract kernel data structures and runtime state from Linux memory samples for post-mortem system analysis.
  • Investigate macOS memory dumps to recover deleted files, encryption keys, and user activity traces.
  • Develop custom plugins to extract domain-specific artifacts from memory for specialized forensic workflows.
  • Research memory forensics techniques and validate new artifact extraction methods against real memory samples.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you work in digital forensics or incident response.

Volatility 3 is the industry-standard memory analysis framework with active maintenance, low install friction, and no known vulnerabilities. The custom VSL license requires review for your use case, but the framework itself is stable and widely adopted. Install it if you need to analyze memory dumps; skip it if you have no forensic analysis requirements.

Install

volatility3 on PyPI

Before you install

Low install friction with a single runtime dependency (pefile). The project is actively maintained with recent commits and a stable release cycle; last commit was 2026-08-14 and the latest release is 2026-04-30.

Requires Python 3.8.0 or later. Symbol table packs for Windows, macOS, and Linux must be downloaded separately and placed in the volatility3/symbols directory; first run with new symbol files requires cache initialization which may take time.

License in practice

Licensed under the Volatility Software License (VSL), which is a custom license distinct from common open-source licenses. The license treatment is marked unclear, so you should review the full VSL v1.0 at https://www.volatilityfoundation.org/license/vsl-v1.0 before using in commercial or redistributed contexts.

Quickstart

pip install volatility3

from volatility3.cli import main

# Run a plugin on a memory sample
vol -f /path/to/memory.vmem windows.info

Verify before relying

  • Whether the VSL license permits commercial use or redistribution without additional restrictions beyond what is stated in the license text.
  • Performance characteristics and memory overhead when analyzing large memory samples.
  • Compatibility with memory dumps from systems other than Windows, macOS, and Linux.

Package facts

LicenseVSL unclear
Python supportSupports the current Python release >=3.8.0
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
pefile
MaintenanceActively maintained 106 days since the last release
Last repo commit
First released
Downloads74,631 / month, #14,809 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: volatility3-2.28.0-py3-none-any.whl

Tags

Capabilities
memory forensics extractionRAM analysis frameworkvolatile memory dump analysisdigital forensics toolsmemory artifact extractionforensic memory imagingsystem memory investigation
Topics
forensicsmemory-analysisincident-response
PyPI keywords
volatilitymemoryforensicsframeworkwindowslinuxvolshell

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “memory forensics extraction”

  • volatility3Volatility 3 is a memory forensics framework that extracts and…
  • ubi-readerExtracts files and analyzes the structure of UBI and UBIFS filesystem…
  • dissect.ntfsParses and reads NTFS file systems, the primary file system used by…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also acquire · py-lets-be-rational · vollib · arch · py-vollib · minidump · quantstats · vnstock · binsize · mozleak