Volatility3

by kirandawadi

2 stars
184 downloads
Not rated
GitHub

About

Perform advanced memory forensics analysis using Volatility3 via a conversational interface. Requires user-specified memory dump files.

Details

Author
kirandawadi
Repository
Kirandawadi/volatility3-mcp
GitHub stars
2
Downloads
184
Categories
Developer Tools, Security, Infrastructure, Productivity, Design, AI, Project Management, Other
Tags
#integration

- Memory Dump Analysis: Analyze Windows and Linux memory dumps using various plugins
- Process Inspection: List running processes, examine their details, and identify suspicious activity
- Network Analysis: Examine network connections to detect command and control servers
- Cross-Platform Support: Works with both Windows and Linux memory dumps (macOS support coming soon)
- Malware Detection: Scan memory with YARA rules to identify known malware signatures

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Volatility3
    Command (node, npx, python, etc.) absolute/path/to/virtual/environment/bin/python3
    Arguments
    • Argument 1 absolute/path/to/bridge_mcp_volatility.py

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

1. Clone this repository:
2. Create a virtual environment:

   python -m venv environ
source environ/bin/activate

3. Install the required dependencies:
   pip install -r requirements.txt

You can use this project in two ways:

initialize_memory_file

Set up a memory dump file for analysis.

detect_os

Identify the operating system of the memory dump.

list_plugins

Display all available Volatility3 plugins.

get_plugin_info

Get detailed information about a specific plugin.

run_plugin

Execute any Volatility3 plugin with custom arguments.

get_processes

List all running processes in the memory dump.

get_network_connections

View all network connections from the system.

list_process_open_handles

Examine files and resources accessed by a process.

scan_with_yara

Scan memory for malicious patterns using YARA rules.

- initialize_memory_file: Set up a memory dump file for analysis
- detect_os: Identify the operating system of the memory dump
- list_plugins: Display all available Volatility3 plugins
- get_plugin_info: Get detailed information about a specific plugin
- run_plugin: Execute any Volatility3 plugin with custom arguments
- get_processes: List all running processes in the memory dump
- get_network_connections: View all network connections from the system
- list_process_open_handles: Examine files and resources accessed by a process
- scan_with_yara: Scan memory for malicious patterns using YARA rules

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "volatility3": {
            "cwd": null,
            "env": {},
            "args": [
                "absolute/path/to/bridge_mcp_volatility.py"
            ],
            "shell": false,
            "command": "absolute/path/to/virtual/environment/bin/python3"
        }
    }
}

Linux

{
    "cwd": null,
    "env": [],
    "args": [
        "absolute/path/to/bridge_mcp_volatility.py"
    ],
    "shell": false,
    "command": "absolute/path/to/virtual/environment/bin/python3"
}

Macos

{
    "cwd": null,
    "env": [],
    "args": [
        "absolute/path/to/bridge_mcp_volatility.py"
    ],
    "shell": false,
    "command": "absolute/path/to/virtual/environment/bin/python3"
}

Windows

{
    "cwd": null,
    "env": [],
    "args": [
        "absolute/path/to/bridge_mcp_volatility.py"
    ],
    "shell": false,
    "command": "absolute/path/to/virtual/environment/bin/python3"
}

Volatility3 MCP Server is a powerful tool that connects MCP clients like Claude Desktop with Volatility3, the advanced memory forensics framework. This integration allows LLMs to analyze memory dumps, detect malware, and perform sophisticated memory forensics tasks through a simple, conversational interface.

You can also find adetailed presentationon this tool here.

Memory forensics is a complex field that typically requires specialized knowledge and command-line expertise. This project bridges that gap by:

- Allowing non-experts to perform memory forensics through natural language
- Enabling LLMs to directly analyze memory dumps and provide insights
- Automating common forensic workflows that would normally require multiple manual steps
- Making memory forensics more accessible and user-friendly

- Memory Dump Analysis: Analyze Windows and Linux memory dumps using various plugins
- Process Inspection: List running processes, examine their details, and identify suspicious activity
- Network Analysis: Examine network connections to detect command and control servers
- Cross-Platform Support: Works with both Windows and Linux memory dumps (macOS support coming soon)
- Malware Detection: Scan memory withYARA rulesto identify known malware signatures
- Clone this repository:
- Create a virtual environment:

python -m venv environ source environ/bin/activate

- Configure Claude Desktop:

- Go toClaude->Settings->Developer->Edit Config->claude_desktop_config.jsonand add the following

{ "mcpServers": { "volatility3": { "command": "absolute/path/to/virtual/environment/bin/python3", "args": [ "absolute/path/to/bridge_mcp_volatility.py" ] } } }

- Start the SSE server:

python3 start_sse_server.py

- Open Cursor settings
- Navigate toFeatures->MCP Servers
- Add a new MCP server with the URLhttp://127.0.0.1:8080/sse

- initialize_memory_file: Set up a memory dump file for analysis
- detect_os: Identify the operating system of the memory dump
- list_plugins: Display all available Volatility3 plugins
- get_plugin_info: Get detailed information about a specific plugin
- run_plugin: Execute any Volatility3 plugin with custom arguments
- get_processes: List all running processes in the memory dump
- get_network_connections: View all network connections from the system
- list_process_open_handles: Examine files and resources accessed by a process
- scan_with_yara: Scan memory for malicious patterns using YARA rules

Contributions are welcome! Please feel free to submit a Pull Request.

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning with Cycode.

Enable AI agents to secure code with Semgrep.

An engineering governance and safety control plane for AI coding agents to enforce strict SDLC discipline, quality gates, and security branch protections.

AI-powered security scanning. Scans code, files, and git diffs for vulnerabilities in real-time using the Armis scanning API.

MCP server that vets LLM-emitted shell commands BEFORE execution. 30 detection rules across destructive file ops, package managers, system, database, git, network, exfiltration, privilege escalation. Sub-second, local, free.

Give your coding agent the dependency graph it is about to change: scan a source tree, SBOM, Git ref, or container image; explain why a package is present; diff two graphs; check findings against policy.

BoostSecurity MCP acts as a safeguard preventing agents from adding vulnerable packages into projects. It analyzes every package an AI agent introduces, flags unsafe dependencies, and recommends secure, maintained alternatives to keep projects protected.

A secure MCP server for executing controlled command-line operations with comprehensive security features.

Access the Codacy API to analyze code quality, coverage, and security for your repositories.

Execute pre-approved shell commands securely on a server.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.