AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified Apache-2.0 Self-run

Volatility Mcp

mcp-gaffx-volatility-mcp · by Gaffx

This repo hosts an MCP server for volatility3.x

No reviews yet
0 installs
20 views
0.0% view→install

Install

$ agentstack add mcp-gaffx-volatility-mcp

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution Used
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-gaffx-volatility-mcp)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
stale · 1y ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Volatility Mcp? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Your AI Assistant in Memory Forensics

Overview

Volatility MCP seamlessly integrates Volatility 3's powerful memory analysis with FastAPI and the Model Context Protocol (MCP). Experience memory forensics without barriers as plugins like pslist and netscan become accessible through clean REST APIs, connecting memory artifacts directly to AI assistants and web applications

Features

  • Volatility 3 Integration: Leverages the Volatility 3 framework for memory image analysis.
  • FastAPI Backend: Provides RESTful APIs to interact with Volatility plugins.
  • Web Front End Support (future feature): Designed to connect with a web-based front end for interactive analysis.
  • Model Context Protocol (MCP): Enables standardized communication with MCP clients like Claude Desktop.
  • Plugin Support: Supports various Volatility plugins, including pslist for process listing and netscan for network connection analysis.

Architecture

The project architecture consists of the following components:

  • MCP Client: MCP client like Claude Desktop that interacts with the FastAPI backend.
  • FastAPI Server: A Python-based server that exposes Volatility plugins as API endpoints.
  • Volatility 3: The memory forensics framework performing the analysis.

This architecture allows users to analyze memory images through MCP clients like Claude Desktop. Users can use natural language prompts to perform memory forensics analysis such as show me the list of the processes in memory image x, or show me all the external connections made

Getting Started

Prerequisites

Installation

  1. Clone the repository:

`` git clone cd ``

  1. Install the required Python dependencies:

`` pip install -r requirements.txt ``

  1. Start the FastAPI server to expose Volatility 3 APIs:

`` uvicorn volatility_fastapi_server:app ``

  1. Install Claude Desktop (see Claude Desktop
  2. To configure Claude Desktop as a volatility MCP client, navigate to Claude → Settings → Developer → Edit Config, locate the claudedesktopconfig.json file, and insert the following configuration details
  3. Please note that the -i option in the config.json file specifies the directory path of your memory image file.

`` { "mcpServers": { "vol": { "command": "python", "args": [ "/ABSOLUTE_PATH_TO_MCP-SERVER/vol_mcp_server.py", "-i", "/ABSOLUTE_PATH_TO_MEMORY_IMAGE/" ] } } } `` Alternatively, update this file directly:

/Users/YOUR_USER/Library/Application Support/Claude/claude_desktop_config.json

Usage

  1. Start the FastAPI server as described above.
  2. Connect an MCP client (e.g., Claude Desktop) to the FastAPI server.
  3. Start the prompt by asking questions regarding the memory image in scope, such as showing me the running processes, creating a tree relationship graph for process x, or showing me all external RFC1918 connections.

Future Features and Enhancements

  • Native Volatility Python Integration: Incorporate Volatility Python SDK directly in the code base as opposed to subprocess volatility binary
  • Yara Integration: Implement functionality to dump a process from memory and scan it with Yara rules for malware analysis.
  • Multi-Image Analysis: Enable the analysis of multiple memory images simultaneously to correlate events and identify patterns across different systems.
  • Adding more Volatility Plugins: add more volatility plugins to expand the scope of memory analysis
  • GUI Enhancements: Develop a user-friendly web interface for interactive memory analysis and visualization.
  • Automated Report Generation: Automate the generation of detailed reports summarizing the findings of memory analysis.
  • Advanced Threat Detection: Incorporate advanced techniques for detecting sophisticated threats and anomalies in memory.

Contributing

Contributions are welcome! Please follow these steps to contribute:

  1. Fork this repository.
  2. Create a new branch (git checkout -b feature/my-feature).
  3. Commit your changes (git commit -m 'Add some feature').
  4. Push to your branch (git push origin feature/my-feature).
  5. Open a pull request.

[](https://mseep.ai/app/gaffx-volatility-mcp)

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.