Skip to content
Volatility memory forensics plugin for extracting Windows DNS Cache
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Type Name Latest commit message Commit time
Failed to load latest commit information.
tools added tool to extract pdb info from command line Feb 12, 2017
.gitignore Initial checkin. Feb 2, 2017 Update Feb 15, 2017
LICENSE fixed some email addresses. Feb 15, 2017 doc update ( Feb 15, 2017 Fixed a retry on GUID in lower case when symbols servers serves the f… Mar 13, 2017


dnscache is a plugin for the Volatility Memory Forensics Platform to extract the Windows DNS Resolver Cache.

The plugin will try to download the .pdb file from microsoft for the dnsrslvr.dll. This behavior can be avoided by providing the file your self.


                          Use this proxy to download .PDB file
      -D DUMP_DIR, --dump_dir=DUMP_DIR
                          Dump directory for .PDB file
                          Server to download .PDB file from
                          Allows you to download the .PDB file off system and
                          provide the reference on the command line
                          Provide path to the cabextract system utility
                          Provide dnsrslvr.dll from the file system.

The plugin will provide more information if the volatility --verbose flag is set (among other things, this will output the download link for the .pdb file if the dnsrslvr.dll is not paged)

% --verbose dnscache -D dump/


Copy the to your plugins directory or point volatility to your checkout directory


% --plugins=/home/geir/src/dnscache dnscache


  • construct (pdbparse dependency) (Feb. 12 2017, see
  • pefile
  • pdbparse
  • requests
  • cabextract (system utility)

Known issues

See the file.


See the file.



  1. Cohen, M. (2014). The Windows User mode heap and the DNS resolver cache. Retrieved from:
  2. Cohen, M. (2014). Source code for Module Retrieved from:
  3. Pulley, C. (2013). Source code for Module (volatility community plugins) Retrieved from:
  4. Ligh, M., Case, A., Levy, J. & Walters, A. (2014). The Art of Memory Forensics.
  5. Levy, J. (2015). dns cache plugin #201 (Volatility Issiues) Retrieved from:


dnscache is released under the ISC License. See the bundled LICENSE file for details.

You can’t perform that action at this time.