This repository contains a sub-set of Volatility plugins that produce output in the CASE/UCO format.
These plugins have been taken from core Volatility plugins and adapted the output to produce CASE/UCO JSON-LD. These currently are proof-of-concept only, and may not fully comply to the CASE/UCOontology as it is an evolving standard.
This repository takes the following plugins from the Volatility framework and adapats the output to be CASE/UCO compliant based on the v0.1.0 release:
All Volatility work belongs to their respective authors which can be found here.
vol.py --plugins='volplugs/src/' -f memory_images/memory.img --profile WinXPSP2x86 casehandles
vol.py --plugins='volplugs/src/' -f memory_images/memory.img caseprocdump --dump-dir dumpdir
vol.py --plugins='volplugs/src/' -f memory_images/memory.img casecmdline