analyze-memory-dump
Perform Volatility analysis on Windows memory dumps to uncover forensic artifacts. Reports plugin failures transparently and marks malfind hits for manual review.
Instructions
Perform bounded, real Volatility analysis of a Windows memory dump inside the evidence root. Returns plugin-level failures honestly; malfind hits require analyst review.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| filePath | Yes | Path to a Windows memory dump located inside EVIDENCE_ROOT. |