mem_plugin
Run read-only Volatility3 plugins to test DFIR hypotheses without altering evidence. Use inspection plugins like pslist, netscan, and malfind for memory analysis.
Instructions
Run a read-only volatility3 plugin by name to test a hypothesis. Plugins that write carved data to disk (dumpfiles, memdump, procdump, ...) and any output/dump flag are refused: VERDICT exposes no write primitive. Use inspection plugins (pslist, netscan, malfind, consoles, cmdline, dlllist, getsids, handles).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| image | Yes | ||
| plugin | Yes | ||
| extra_args | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |