Difference between pages "Volatools" and "Tcpxtract"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m
 
m (Initial Stub)
 
Line 1: Line 1:
 
{{Expand}}
 
{{Expand}}
{{Infobox_Software |
 
  name = volatools |
 
  maintainer = [[AAron Walters]] and [[Nick Petroni]] |
 
  os = {{Windows}} |
 
  genre = [[Windows Memory Analysis]] |
 
  license = {{GPL}} |
 
  website = [http://komoku.com/forensics/forensics.html komoku.com] |
 
}}
 
  
The Volatools suite is a set of tools by [[Komoku]] for conducting [[Windows Memory Analysis|memory analysis]]. The current version, '''Volatools Basic''', can process images from [[Windows XP]] Service Pack 2 systems. A forthcoming version '''Volatools Professional''' should be able to process images from more platforms. Although the Volatools are written in [[Python]] and are therefore cross-platform, they require the [[Pykvm]] library that is only available for [[Windows]].
+
Inspired by [[foremost]], this tool by [[Nick Harbour]] can recover files from network traffic based on their headers and footers.
  
== License ==
+
== External Links ==  
  
The Volatools are licensed under the [[:Category:GPL|GPL]]. Some of the functionality for these tools is contained in a closed source library called [[Pykvm]].
+
* [http://tcpxtract.sourceforge.net Official website]
 
+
== History ==
+
 
+
Volatools Basic was first released at the [[Blackhat (conference)|Blackhat Federal]] conference in February 2007. The professional version and an acquisition product, '''Komoku Acquisition Suite''' are scheduled to be released in 2007.
+
 
+
== External Links ==
+
 
+
* [http://komoku.com/forensics/forensics.html Volatools official website]
+

Latest revision as of 21:54, 1 March 2007

Information icon.png

Please help to improve this article by expanding it.
Further information might be found on the discussion page.

Inspired by foremost, this tool by Nick Harbour can recover files from network traffic based on their headers and footers.

External Links