An open API service indexing awesome lists of open source software.

https://github.com/serialphotog/linux-memory-analysis-tools

Various POC tools for dumping and scanning the memory on a Linux system.
https://github.com/serialphotog/linux-memory-analysis-tools

forensics linux memory-forensics proof-of-concept

Last synced: 9 months ago
JSON representation

Various POC tools for dumping and scanning the memory on a Linux system.

Awesome Lists containing this project

README

          

# Linux Memory Analysis Tools

This repository contains some proof-of-concept tools for working with memory analysis on Linux. These work by locating the physical RAM address ranges by processing `/proc/iomem` and associating with regions in `/proc/kcore`. There are currently two tools provided here:

1. `dumpmemory` - Dumps the physical RAM of the system to a file on disk:

```
dumpmemory
```
2. `scanmemory` - Scans the system memory for a specified string pattern. Technically there's not many circumstances where you'd want this, but it serves as a POC of how something like this could work:

```
scanmemory
```

## Disclaimer

Note that these tools are nothing more than experimental proofs-of-concept. They have not been extensively tested and I make no guarantee about their accuracy or completeness.

## Building

```bash
make
```