H3AD-REF / CHEATSHEETS / VOLATILITY 3 COMMANDS

Volatility 3 Commands.
Dotted Plugin Names, Not Guesswork.

A static plugin reference for Volatility 3, the Python 3 rewrite of the framework. Every plugin below uses the dotted windows.* naming Volatility 3 ships with, not the bare names from older Volatility 2 writeups. No memory image runs here, just the syntax and what each plugin actually catches.

Basic Syntax

One invocation shape covers almost every plugin below. Learn this once and the rest is just picking the right plugin name.

Base Command Pattern

Base invocation
vol -f <image> <plugin.name>
└── file first, dotted plugin name second, this shape holds across the whole framework
    // e.g. vol -f memory.dmp windows.pslist

--pid <pid>
Filters most process-scoped plugins down to a single process ID
    // works with cmdline, dlllist, handles, vadinfo, malfind, and similar per-process plugins

-o <dir> and --dump
Sets an output directory and triggers extraction on dumpfiles-style plugins
    // skip -o and dumped artifacts land in the current working directory instead

-h and <plugin> --help
Lists the option set a given plugin accepts
    // option flags differ per plugin, check before assuming one exists

Process Analysis

Enumerating processes two different ways matters more than picking one. A linked-list walk and a pool scan don't always agree, and the disagreement is the finding.

PROCESS

Active Process Listing

windows.pslist
Walks the EPROCESS linked list to enumerate active processes. Fast and simple, but a process that's been unlinked from that list by malware won't show up here at all.
PROCESS

Process Hierarchy

windows.pstree
Builds parent-to-child relationships from the same process data as pslist, laid out as a tree. Useful for spotting a process spawned from somewhere it has no business coming from.
PROCESS

Pool-Scan Process Recovery

windows.psscan
Scans the pool allocator directly instead of walking a linked list, so it catches hidden or already-terminated processes that pslist misses. Run it alongside pslist and compare the two lists.
PROCESS

Command-Line Arguments

windows.cmdline
Recovers the command-line string each process was launched with. Add --pid to pull the argument line for one process instead of scanning the whole image.
PROCESS

Loaded DLLs

windows.dlllist
Lists the DLLs loaded into each process's address space, including path and load order. A process with an unexpected DLL loaded from a temp or user-writable path is worth a second look.
PROCESS

Open Handles

windows.handles
Enumerates open handles per process: files, registry keys, mutexes, and more. A mutex name reused across samples is often the fastest way to cluster related activity.
PROCESS

Virtual Address Layout

windows.vadinfo
Dumps the virtual address descriptor tree for a process, showing how its memory is regioned and protected. It's the map malfind reads before flagging anything.

Network Analysis

Two plugins, two methods. The pool scan is slower and more thorough; the walk is faster and can miss what's already been unlinked.

NETWORK

Pool-Scan Connections

windows.netscan
Finds network connections and sockets by scanning the pool allocator rather than walking a structure list. The more reliable of the two network plugins on modern Windows, and the one to reach for first.
NETWORK

Walk-Based Connections

windows.netstat
Enumerates connections by walking the relevant kernel structures. Runs faster than netscan but can miss a connection that's been unlinked, so treat a clean netstat result as a lead, not a conclusion.

Malware & Code Injection

The checks that separate a memory image with an infection from one that just has a lot of running processes.

MALWARE

Injected Code Detection

windows.malfind
Flags memory regions marked read-write-execute that also contain an embedded PE header. This is the standard first check for process injection in any Volatility 3 workflow.
MALWARE

Process Hollowing Detection

windows.hollowprocesses
Compares a process's on-disk image against what's actually mapped in memory, and flags the mismatch that process hollowing leaves behind.
MALWARE

SSDT Hook Scan

windows.ssdt
Scans the system service descriptor table for hooked entries. A modified table entry pointing outside the expected kernel module range is the signal to chase.
MALWARE

Loaded Driver Enumeration

windows.driverscan
Enumerates loaded kernel drivers. Pair it with a hash or signature check against known-good driver sets rather than eyeballing the list alone.

Registry & Credentials

Registry hives and the secrets sitting in them, local accounts, cached domain logons, and LSA secrets alike.

REGISTRY

Loaded Hive Locations

windows.registry.hivelist
Lists every registry hive loaded in memory along with its file path, the starting point before pulling any specific key.
REGISTRY

Registry Key Dump

windows.registry.printkey
Dumps the values under a specific registry key. Needs a key path, so run hivelist first if you're not sure which hive holds it.
REGISTRY

SAM NTLM Hashes

windows.hashdump
Extracts local account hashes from the SAM hive in the format user:RID:LM:NTLM. Local accounts only, not domain credentials.
REGISTRY

Cached Domain Credentials

windows.cachedump
Pulls cached domain credential hashes from the registry, the ones Windows keeps around so a domain-joined machine can still authenticate a user while offline.
REGISTRY

LSA Secrets

windows.lsadump
Dumps LSA secrets from the registry: service account passwords, auto-logon credentials, and other secrets the LSA stores at rest.

Filesystem

Files don't need to still exist on disk to be recoverable. If a file object was open in memory when the image was captured, it can come back out.

FILESYSTEM

File Object Listing

windows.filescan
Lists file objects present in memory at capture time, including files that were open but never touched disk again before the image was taken.
FILESYSTEM

Extract By Virtual Address

windows.dumpfiles --virtaddr <addr>
Extracts a specific file object using its virtual address, usually one pulled straight from a filescan result.
FILESYSTEM

Extract By Physical Address

windows.dumpfiles --physaddr <addr>
Extracts a file object by physical address instead of virtual, useful when the virtual mapping alone doesn't get you a clean recovery.

Command History

What got typed and what got printed to the console are two different recoveries, and only one of them is reliable on a modern build.

HISTORY

Console Command History

windows.cmdscan
Recovers command-line history from console input buffers. Known to be unreliable on modern Windows builds, so don't treat a miss here as proof nothing was typed.
HISTORY

Console Session Output

windows.consoles
Dumps the full output buffer from console sessions, the actual screen contents rather than just what was typed. Often recovers more than cmdscan does.

Misc

One plugin to run before anything else, one to run once you already know what you're hunting for.

MISC

Image Profile Info

windows.info
Reports OS version, architecture, and kernel base address for the image. Run this first on any new memory dump, before anything else, to confirm Volatility identified the right profile.
MISC

YARA Scan Across Process Memory

windows.vadyarascan
Runs a YARA rule against every process's memory space in the image. Writing the rule first? The YARA rule-writing guide covers rule anatomy and the pitfalls that make a rule noisy.