Briefly, here are some of the features of volshell:
- Shell is a full Python interpreter, so all the power of Python can be leveraged.
- Uses Volatility 1.3 object model for easy access to data structures in memory.
- Can use iPython for the underlying shell if available, which enables some nice features.
- Commands modelled after WinDbg.
- Works with any memory image format that Volatility supports (dd, crash, vmem, hibernation file)
$ python volatility volshell -f $IMAGE