Skip to main content

Pakunoda

pakunoda

Extract Volatility 3 ISF profiles from raw Linux memory dumps via BTF and kallsyms.

Volatility 3 needs a symbol profile (ISF JSON) that matches the exact kernel of the machine you captured. Normally you build one with dwarf2json from a vmlinux with debug symbols, which means tracking down the matching kernel debug package — often impossible for an unknown or long-decommissioned host. pakunoda skips that step entirely: it reads the metadata the kernel embeds about itself in its own .rodata (BTF type information, the kallsyms symbol table, and the linux_banner string) out of the raw dump and reconstructs the ISF profile directly. No vmlinux, no debug packages, no matching kernel, no network access.

Installation

Requires Python 3.10 or later.

git clone https://github.com/monkeywave/pakunoda.git
cd pakunoda
pip install -e .

To run the test suite, install the development extras instead:

pip install -e ".[dev]"
pytest

Usage

Generate a profile from a dump. With no -o, the profile is written next to the dump as <dumpname>_profile.isf.json:

pakunoda extract my-webserver-new.lime

Point -o at a directory (existing, or with a trailing slash to have it created) to write the default filename inside it:

pakunoda extract my-webserver-new.lime -o ~/cases/webserver/

Or name the output file exactly:

pakunoda extract my-webserver-new.lime -o webserver.isf.json

Other commands:

  • pakunoda probe <dump> — report which artifacts (banner, DTB, BTF, kallsyms) were found and where, without generating a profile.
  • pakunoda info <isf.json> — summarise an ISF file: type and symbol counts, the kernel banner, and whether key structs are present.
  • pakunoda validate <isf.json> — check an ISF file against the Volatility 3 schema. --strict also fails on warnings.

Common flags: --arch selects the target architecture (default auto), -v enables verbose logging, -q suppresses everything but errors, and --json switches to machine-readable output for scripting.

Example

$ pakunoda extract my-webserver-new.lime
pakunoda v0.5.0 — Volatility 3 ISF extractor
Dump: my-webserver-new.lime
Arch: auto

Detected arch: x86_64
ISF generated: /home/analyst/cases/my-webserver-new_profile.isf.json
  Types: 12043  Symbols: 8587  Enums: 743  Base types: 12
  Kernel: 6.12.48+deb13-amd64
  Time: 23.71s

Ready to use with Volatility 3:
  vol -f my-webserver-new.lime -s /home/analyst/cases linux.pslist
  vol -f my-webserver-new.lime -s /home/analyst/cases linux.lsmod

If Vol3 shows errors or empty results, clear its symbol cache:
  rm -f ~/.cache/volatility3/identifier.cache
Also ensure no other ISF files with the same kernel exist under the -s directory.

Using the result with Volatility 3

Pass the directory holding the generated ISF file to Volatility 3 as its symbol directory:

vol -f my-webserver-new.lime -s /home/analyst/cases linux.pslist

Volatility 3 caches which ISF file matches which kernel banner. If it reports errors or returns empty results after you generate a new profile, clear that cache:

rm -f ~/.cache/volatility3/identifier.cache

Also make sure no other ISF file for the same kernel sits under the -s directory, or Volatility 3 may pick the wrong one.

What it needs from the dump

BTF and kallsyms both live in the kernel's .rodata section, so a dump that captured kernel memory normally contains everything pakunoda needs. BTF is present on kernels built with CONFIG_DEBUG_INFO_BTF, which covers mainstream distribution kernels from roughly 5.2 onwards. When BTF is absent — older kernels, or a custom build without it — pakunoda falls back to identifying the kernel by structure detection and selecting a donor profile whose layout matches what the dump actually contains.

That donor comes from a local cache of prebuilt ISFs under ~/.cache/pakunoda/, which is optional and only consulted on the no-BTF path. If you work with pre-BTF kernels (CentOS 7, Debian 9, older custom builds) and want to build one, see docs/PROFILE_CACHE.md — it covers what the cache buys you, how donor selection is graded and recorded in the output, and the exact steps to build a cache of your own. For modern kernels you can ignore it entirely.

Supported architectures are x86-64 and ARM64. Dumps in raw, LiME, and ELF core formats are read directly.

Note on --research

--research enables prototype research algorithms (structural analysis, profile HMMs, constellation-based reconstruction) that are part of the ongoing research behind the tool. They are off by default and are not needed for normal extraction — the default path is the one you want. Use pakunoda extract <dump> --research-list to see what is available.

Further reading

For reproducing the results in the accompanying paper, see README_ARTIFACT.md.

Licence

Apache-2.0.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pakunoda-0.7.0.tar.gz (25.1 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pakunoda-0.7.0-py3-none-any.whl (572.2 kB view details)

Uploaded Python 3

File details

Details for the file pakunoda-0.7.0.tar.gz.

File metadata

  • Download URL: pakunoda-0.7.0.tar.gz
  • Upload date:
  • Size: 25.1 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for pakunoda-0.7.0.tar.gz
Algorithm Hash digest
SHA256 d61b3494d17ad1fb8306ee26f36470ebf766e5c799092a55460a866501f7bfa8
MD5 6ea2505d98fb4c4c835da84dfae5f1ba
BLAKE2b-256 cc27a86a504fe165f43b181eecdfad1afd7a28d2b8396b0a99278f1b09ce897b

See more details on using hashes here.

Provenance

The following attestation bundles were made for pakunoda-0.7.0.tar.gz:

Publisher: publish.yml on monkeywave/pakunoda

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pakunoda-0.7.0-py3-none-any.whl.

File metadata

  • Download URL: pakunoda-0.7.0-py3-none-any.whl
  • Upload date:
  • Size: 572.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for pakunoda-0.7.0-py3-none-any.whl
Algorithm Hash digest
SHA256 5f8b9975d6423d4981e330dc88055c55cb921a68bff1727120b380900e66fd32
MD5 e3fa9a4202fc4f06bce10a9b2fce0894
BLAKE2b-256 f3ac6f7ff30f3498c2305e4310b9c85f973d60981c563681f601143dd89b8d69

See more details on using hashes here.

Provenance

The following attestation bundles were made for pakunoda-0.7.0-py3-none-any.whl:

Publisher: publish.yml on monkeywave/pakunoda

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.9.7

2 files

0.9.6

2 files

0.9.3

2 files

0.9.1

2 files

0.9.0

2 files

0.8.5

2 files

0.8.0

2 files

This release

0.7.0 This release

2 files

0.6.0

2 files

0.5.0

2 files

0.3.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page