volatility3-mcp

Kirandawadi/volatility3-mcp

3.6

Volatility3 MCP Server is a tool that integrates MCP clients with the Volatility3 memory forensics framework, enabling LLMs to perform memory forensics tasks through a conversational interface.

Tools

Functions exposed to the LLM to take actions

initialize_memory_file

Set up a memory dump file for analysis.

detect_os

Identify the operating system of the memory dump.

list_plugins

Display all available Volatility3 plugins.

get_plugin_info

Get detailed information about a specific plugin.

run_plugin

Execute any Volatility3 plugin with custom arguments.

get_processes

List all running processes in the memory dump.

get_network_connections

View all network connections from the system.

list_process_open_handles

Examine files and resources accessed by a process.

scan_with_yara

Scan memory for malicious patterns using YARA rules.

Prompts

Interactive templates invoked by user choice

No prompts

Resources

Contextual data attached and managed by the client

No resources