/volatility-profiles

My Linux profiles built for Volatility 2/3

volatility-profiles

My blog post Building a Linux profile for Volatility 2 and 3:

https://forensenellanebbia.blogspot.com/2021/02/building-profile-for-volatility-2-and-3.html

Copy the profile files to:

  • Volatility 2: ~/volatility/volatility/plugins/overlays/linux/
  • Volatility 3: ~/volatility3/volatility3/symbols/linux/

Useful resources

Red Hat Enterprise Linux (RHEL)

Register your installation to install packages from redhat repo:

subscription-manager register --org=ORG ID --activationkey=Key Name

Install these packages:

dnf install gcc make elfutils-libelf-devel

CentOS

Fedora

SUSE Linux Enterprise Server (SLE)

libdwarf/dwarfdump