Hal Pomeranz on Nostr: feld Memory forensic tools like AVML can use /proc/kcore to extract full RAM memory ...
feld (npub1yck…ujmw) Memory forensic tools like AVML can use /proc/kcore to extract full RAM memory dumps. From there, individual process memory can be extracted with tools like Volatility.
Published at
2023-08-06 16:28:22Event JSON
{
"id": "599b979822a118b86b3bbb6ab608b51164a6476f308cc8bb596cd066f5cf5afc",
"pubkey": "fa8a3ecc28f5281dcf43d9313788b894dff44fba05bc1fd1af3667248894bd59",
"created_at": 1691339302,
"kind": 1,
"tags": [
[
"p",
"262d5a8a8201b6e0804087a9d26929935c7ac6682875b13fe24a5314a04a6cbf",
"wss://relay.mostr.pub"
],
[
"e",
"8d83af7243e712ef71343d60f729f6e81a1f2ce87b875c70cfb1bff75c915e40",
"wss://relay.mostr.pub",
"reply"
],
[
"proxy",
"https://infosec.exchange/users/hal_pomeranz/statuses/110843612521642590",
"activitypub"
]
],
"content": "nostr:npub1yck44z5zqxmwpqzqs75ay6ffjdw843ng9p6mz0lzfff3fgz2djlsngujmw Memory forensic tools like AVML can use /proc/kcore to extract full RAM memory dumps. From there, individual process memory can be extracted with tools like Volatility.",
"sig": "6713bcac8a14716ee544cad217975bed752c6457ce4d143cbafd537614b2a8a360524a7edfab7d802675078ff5ef96980bf6491999e3230cb9afc9b981281d99"
}