/AutoVol

Automates volatility3 for windows with these plugins: info, pslist, pstree, netscan, netstat, cmdline and immediately output all those to a txt and tsv for easier data handling/manipulation with Autofilter to parse data better

Primary LanguagePython

AutoVol

Automates volatility3 for windows with these plugins: info, pslist, pstree, netscan, netstat, cmdline and immediately output all those to a txt and tsv for easier data handling/manipulation with Autofilter to parse data better

Usage

python autovol.py

Insert your sample path:

C:\Memory Forensics\Sample\MemoryDump.dmp

That's it, program will start hash the memorydump in MD5 and SHA1, get the current date and time and put into the corresponding output with all those info as well.