Legal Cyber Academy
Free trainingPartly freeCurrent

Volatility Framework and Volatility Foundation Training

Access and status

Cost

Partly free

Part of it is free and part is not. The entry says which part; read that before you plan around it.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The Volatility Foundation keeps the Volatility Framework — currently Volatility 3 — free and open source on GitHub, with the accompanying project documentation. Separately it endorses instructor-led memory forensics courses; the Foundation's site does not publish prices for those, and the Malware and Memory Forensics class is a commercial offering run through memoryanalysis.net.

Who it is for, and when

What is definitely free is the framework and its documentation, which is the de facto standard for memory analysis and the thing you will be asked about if you testify to a memory finding. Working through the plugin documentation against a public memory image is a legitimate self-study route. Treat the endorsed courses as paid unless a price page says otherwise.

What it does not cover

The free material is reference documentation, not a course: no curriculum, no exercises, no instructor. It covers memory only — nothing on disk imaging, mobile, cloud or reporting — and the structured teaching sits in the paid classes.

Go to the source

Open at volatilityfoundation.org (opens in a new tab)

https://volatilityfoundation.org/

Details

Type
Free training
Written for
Working examinerAdvancedWorking examiner, Advanced
Topics
free-training, memory-forensics, malware, scripting, windows, linux
Checked at source
  • Memory acquisition and analysis across Windows, Linux and macOS, written by the people who built Volatility: process and kernel structures, code injection, rootkit detection, registry and event logs recovered from RAM, the GUI subsystem, network state, and case studies.

  • An open-source memory analysis framework that parses RAM images into processes, network state, loaded modules, injected code, registry hives resident in memory, and command history. Volatility 3 is the actively developed line; Volatility 2 is legacy and should not be the basis of new work, though its documentation is still used for plugin comparison.

  • An Open edX platform hosting long-form, university-length classes in low-level computing: x86-64 assembly, OS internals, firmware and UEFI, debuggers (WinDbg, GDB, IDA, Ghidra, Binary Ninja, HyperDbg), reverse engineering, vulnerability classes, exploitation, fuzzing, trusted computing and Bluetooth security. Actively maintained — 2025 additions include AFL++ fuzzing, Bluetooth reconnaissance and TPM programming in Python, with an introductory emulator course listed for 2026.

  • 13Cubed

    Partly free

    A YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.

  • A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.