MuhammadLab
Digital ForensicsBrowser-local

Volatility Visualizer

Visualise Volatility 3 JSON outputs from Windows memory dumps with browser-local process, file, image, text, network, registry, malfind, recovery-helper, and report views.

This tool does not parse raw memory dumps. Run Volatility locally, export plugin results as JSON, and upload those JSON outputs here.

1

Choose memory dump filename

2

Copy and run Volatility commands

3

Upload generated JSON outputs

4

Explore processes, files, Notepad traces, images, network artefacts, and suspicious memory

Command Generator

mkdir output
vol.exe -f memdump-001.mem -r json windows.info > output\memory_info.json
vol.exe -f memdump-001.mem -r json windows.pslist > output\pslist.json
vol.exe -f memdump-001.mem -r json windows.pstree > output\pstree.json
vol.exe -f memdump-001.mem -r json windows.cmdline > output\cmdline.json
vol.exe -f memdump-001.mem -r json windows.filescan > output\filescan.json
vol.exe -f memdump-001.mem -r json windows.handles > output\handles.json
vol.exe -f memdump-001.mem -r json windows.netscan > output\netscan.json

Upload Volatility JSON Outputs

Upload Volatility JSON outputs here

Accepts multiple .json files. Processing stays in this browser.

Overview

Uploaded files count

0

Processes found

0

File references found

0

Image references found

0

Text references found

0

Notepad-related artefacts found

0

Network connections found

0

Suspicious memory entries found

0

Registry hives found

0

Memory image filename

memdump-001.mem

Analysis mode

Volatility JSON visualisation

Raw memory uploaded

No

Browser-local processing

Yes

This tool processes uploaded Volatility JSON outputs locally in your browser. Do not upload raw memory dumps. Do not upload evidence containing sensitive data to public systems unless authorised.