Memory Forensics Resources

I found a bunch of free resources for memory images when I wanted to do a deeper dive into memory forensics linked from the volatility wiki, only to be stymied by 404s from people hosting things in personal dropbox links or the like. After some Google-fu, I found archived copies of things, and am now hosting mirrors of the more helpful items…

… in my own Dropbox to 404 out sometime in the future. Hey, it’s hard to find free hosting of larger files indefinitely!

Downloads

Interesting Memory Images

Tools

  • Sift Workstation - comes with volatility, rekall and a number of other DFIR tools configured and installed.

Resources

Other People’s Analysis