This program allows the user to have access in a Memory Dump. It can also work as a plugin to the Volatility Framework (https://github.com/volatilityfoundation/volatility).
The program works similarly to Process Explorer / Chippers, but additionally allows the user to access a Memory Dump (or access real-time memory on the computer, using Memtriage).
It can be run by Windows, Linux and MacOS machines, but can only use Windows memory images.
Installation
git clone https://github.com/memoryforensics1/VolExp cd VolExp python2 volexp python2 vol.py -f--profile= volexp python2 memtriage.py --plugins=volexp
Application snapshots
You will find information about the program here.
You can download the program from here.