Here is a guide on how to remotely dump Linux RAM with┬áLiMEaide –┬áa python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your forensic workstation.

The process includes six steps:

  1. Make a remote connection with specified client over SSH
  2. Transfer necessary build files to the remote machine
  3. Build the memory scrapping Loadable Kernel Module (LKM) LiME
  4. LKM will dump RAM
  5. Transfer RAM dump and RAM maps back to host
  6. Build a Volatility profile

 

Load More Related Articles
Load More In How To

Leave a Reply

Your email address will not be published. Required fields are marked *