# Velociraptor vs Volatility 3

| Attribute | Velociraptor | Volatility 3 |
|---|---|---|
| **Vioscale score** | 24.3 (3% (low)) | 43.9 (31% (low)) |
| activity.commits_last_30d | - | 11 |
| adoption.dependent_repos | - | 10 |
| adoption.github_stars | - | 4,357 |
| deployment.options | `{"cloud":true,"hybrid":true,"on_prem":true,"air_gapped":true,"self_hosted":true}` | `{"self_hosted":true}` |
| description.long | A digital forensic and incident response tool that enables targeted collection and analysis of forensic evidence from endpoints simultaneously, with capabilities for artifact hunting, event log analysis, and endpoint monitoring. | An open-source framework for analyzing RAM samples and extracting digital artifacts independent of the operating system. Supports Windows, Mac, and Linux memory analysis and is used for incident response and malware investigation. |
| features.capabilities | - | `{"pricing_model":"open_source","deployment_model":"portable_cli","disk_imaging_file_carving":false,"cloud_saas_m365_extraction":false,"remote_endpoint_acquisition":false,"volatile_memory_ram_analysis":true,"mobile_ios_android_extraction":false}` |
| integrations.count | 6 | - |
| integrations.list | `[{"name":"Slack"},{"name":"Discord"},{"name":"S3"},{"name":"SMB"},{"name":"Azure OAuth"},{"name":"Google OAuth"}]` | - |
| language.primary | - | Python |
| platform.support | `{"cli":true,"mac":true,"web":true,"linux":true,"windows":true}` | `{"cli":true,"mac":true,"linux":true,"windows":true}` |
| pricing | - | `{"type":"open_source","sourceUrl":"https://volatilityfoundation.org","retrievedAt":"2026-08-21T12:42:00.261Z"}` |
| pricing.model | - | commercial |
| pricing.price_level | - | free |
| pricing.transparent | - | yes |
| release.cadence_days | - | 126 |
| release.history | - | `[{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.28.0","date":"2026-04-30T19:57:16Z","type":"stable","version":"v2.28.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.27.0","date":"2026-01-29T21:51:57Z","type":"stable","version":"v2.27.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.26.2","date":"2025-09-25T20:51:37Z","type":"stable","version":"v2.26.2"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.26.0","date":"2025-05-16T13:24:53Z","type":"stable","version":"v2.26.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.11.0","date":"2025-01-16T20:24:58Z","type":"stable","version":"v2.11.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.8.0","date":"2024-10-09T22:28:48Z","type":"stable","version":"v2.8.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.7.0","date":"2024-05-29T19:45:32Z","type":"stable","version":"v2.7.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.5.2","date":"2024-01-31T21:35:24Z","type":"stable","version":"v2.5.2"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.5.0","date":"2023-09-27T19:55:43Z","type":"stable","version":"v2.5.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.4.1","date":"2023-04-12T19:33:00Z","type":"stable","version":"v2.4.1"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.4.0","date":"2022-12-14T20:10:23Z","type":"stable","version":"v2.4.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.0.1","date":"2022-03-17T20:37:48Z","type":"stable","version":"v2.0.1"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v2.0.0","date":"2022-01-12T22:11:49Z","type":"stable","version":"v2.0.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v1.0.1","date":"2021-02-01T19:47:56Z","type":"stable","version":"v1.0.1"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v1.0.0","date":"2021-02-01T17:11:28Z","type":"stable","version":"v1.0.0"},{"url":"https://github.com/volatilityfoundation/volatility3/releases/tag/v1.0.0-beta.1","date":"2019-10-13T10:52:15Z","type":"prerelease","version":"v1.0.0-beta.1"}]` |
| security.disclosure_policy | yes | - |
| security.scorecard | - | 4.6 |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=volatility3&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (Digital Forensics)

| Capability | Velociraptor | Volatility 3 |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Deployment model | - | Portable CLI |
| Disk imaging file carving | - | ✗ |
| Volatile memory RAM analysis | - | ✓ |
| Mobile ios android extraction | - | ✗ |
| Remote endpoint acquisition | - | ✗ |
| Mac os apfs support | - | - |
| Cloud saas m365 extraction | - | ✗ |
| Court admissible hashing reporting | - | - |
| Automated artifact timelining | - | - |
| Malware triage yara scanning | - | - |
| Fips 140 2 certification | - | - |
| SOC2 type ii | - | - |
| Pricing model | - | Open source |

*Source: Vioscale. Generated 2026-09-01T15:18:40.981Z. "-" = undocumented, not absent.*
