3.1.1 Volatility Standalone Executable

The fastest way to get started with Volatility is to use the standalone executable. The standalone executable is distributed for Windows, macOS, and Linux operating systems. The advantage of a standalone executable is that you don't need to install the Python interpreter or Volatility dependencies, since it comes packaged with Python 2.7 Interpreter and all the required dependencies.

On Windows, once the standalone executable is downloaded, you can check whether Volatility is ready to use by executing the standalone executable with the -h (--help) option from the command line, as shown here. The help option displays various options and plugins that are available in Volatility:

C:\volatility_2.6_win64_standalone> ...

Get Learning Malware Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.