Reputation: 1
How to run volatility directly on RAM of a running VM, without need to get memory dump first?
Upvotes: 0
Views: 314
Reputation: 101
Volatility is not designed for analysis on live systems.
If you need to get VM's process list using a memory forensics framework and you're interested in live analysis of hypervisor, I suggest you to use Rekall:
VM discovery and introspection with Rekall
Upvotes: 1