Kyeong-Sik Lee and the Korean Digital Forensic Research Center have released Volafox, a free and open-source tool to analyze Mac OS X memory images. Volafox is based on work by Matthieu Suiche (paper and slides) and the Volatility memory analysis framework.
Tuesday, June 14, 2011
Analyzing OSX Memory Images with Volafox
I have learned via room362's twitter , volatility and computer.forensikblog.de that there is an open-source tool called Volafox that is able to analyze Mac OSX memory images. This tool is written in python and is built on top of Volatility.