Volatility 3 Commands.
Dotted Plugin Names, Not Guesswork.
A static plugin reference for Volatility 3, the Python 3 rewrite of the framework. Every plugin below uses the dotted windows.* naming Volatility 3 ships with, not the bare names from older Volatility 2 writeups. No memory image runs here, just the syntax and what each plugin actually catches.
Basic Syntax
One invocation shape covers almost every plugin below. Learn this once and the rest is just picking the right plugin name.
Base Command Pattern
Base invocation vol -f <image> <plugin.name> └── file first, dotted plugin name second, this shape holds across the whole framework // e.g. vol -f memory.dmp windows.pslist --pid <pid> Filters most process-scoped plugins down to a single process ID // works with cmdline, dlllist, handles, vadinfo, malfind, and similar per-process plugins -o <dir> and --dump Sets an output directory and triggers extraction on dumpfiles-style plugins // skip -o and dumped artifacts land in the current working directory instead -h and <plugin> --help Lists the option set a given plugin accepts // option flags differ per plugin, check before assuming one exists
Process Analysis
Enumerating processes two different ways matters more than picking one. A linked-list walk and a pool scan don't always agree, and the disagreement is the finding.
Active Process Listing
windows.pslistProcess Hierarchy
windows.pstreePool-Scan Process Recovery
windows.psscanCommand-Line Arguments
windows.cmdline--pid to pull the argument line for one process instead of scanning the whole image.Loaded DLLs
windows.dlllistOpen Handles
windows.handlesVirtual Address Layout
windows.vadinfoNetwork Analysis
Two plugins, two methods. The pool scan is slower and more thorough; the walk is faster and can miss what's already been unlinked.
Pool-Scan Connections
windows.netscanWalk-Based Connections
windows.netstatMalware & Code Injection
The checks that separate a memory image with an infection from one that just has a lot of running processes.
Injected Code Detection
windows.malfindProcess Hollowing Detection
windows.hollowprocessesSSDT Hook Scan
windows.ssdtLoaded Driver Enumeration
windows.driverscanRegistry & Credentials
Registry hives and the secrets sitting in them, local accounts, cached domain logons, and LSA secrets alike.
Loaded Hive Locations
windows.registry.hivelistRegistry Key Dump
windows.registry.printkeySAM NTLM Hashes
windows.hashdumpuser:RID:LM:NTLM. Local accounts only, not domain credentials.Cached Domain Credentials
windows.cachedumpLSA Secrets
windows.lsadumpFilesystem
Files don't need to still exist on disk to be recoverable. If a file object was open in memory when the image was captured, it can come back out.
File Object Listing
windows.filescanExtract By Virtual Address
windows.dumpfiles --virtaddr <addr>Extract By Physical Address
windows.dumpfiles --physaddr <addr>Command History
What got typed and what got printed to the console are two different recoveries, and only one of them is reliable on a modern build.
Console Command History
windows.cmdscanConsole Session Output
windows.consolesMisc
One plugin to run before anything else, one to run once you already know what you're hunting for.
Image Profile Info
windows.infoYARA Scan Across Process Memory
windows.vadyarascan