Document Type

Conference Proceeding

Publication Date



Memory analysis has become a critical capability in digital forensics because it provides insight into system state that cannot be fully represented through traditional media analysis. The volafox open source project has begun the work of structured memory analysis for OS X with support for a limited set of kernel structures. This paper addresses one memory analysis deficiency on OS X with the introduction of a new volafox module for parsing file handles associated with running processes. The developed module outputs information comparable to the UNIX lsof (list open files) command, which is used to validate the results.


AFIT Scholar furnishes a draft of this presentation.

Code related to this research is available at an external repository.

License: GNU GPL v2. This link to the code repository will not be accessible from most DOD networks.