This is just another GUI for volatility and yara which could make someone's life easier. It is inteded for Incident responders for quick examination of a memory image. Results are stored in sqlite db for reuse.
Clone repo
git clone https://Ft44k@bitbucket.org/Ft44k/yavol.git
- default forder for yara sigs is /yara_rules
you need to have installed Python (2.7), PyQt4, and sqlite3
GPLv3 license, see LICENSE.txt
for details.
I would like to thank to my wife for tolerance an patience for my little projects. Also my thanks goes to all people who helped me to overcome the learning curve. I don't know them, but google found them on StackExchange :) Hope I will find some other people here who would like to contribute to make this small utility even better.