Glossary
LiME (Linux Memory Extractor)
LiME is a loadable Linux kernel module that dumps physical memory to a file or a TCP socket for later analysis with Volatility or other tools.
LiME, the Linux Memory Extractor, is an open source loadable kernel module (github.com/504ensicsLabs/LiME) that acquires a copy of physical memory from a running Linux or Android system. Because it runs inside the kernel, it can read RAM directly without relying on /dev/mem or /proc/kcore, which are often restricted on modern distributions.
The module is configured through parameters passed to insmod. path is either a file on external media or tcp:<port> to stream the image to an analyst workstation, and format selects lime (ranges prefixed with address headers, the preferred format for Volatility), raw or padded.
insmod lime-$(uname -r).ko "path=tcp:4444 format=lime"
The main operational constraint is that a kernel module must match the running kernel version and configuration. You have to compile LiME against the correct kernel headers ahead of time, on a trusted build system, and systems enforcing module signatures may refuse to load it. Loading a module also modifies kernel state, so record it in your notes. Userland alternatives such as AVML avoid the build step. See Linux memory forensics with LiME and Volatility.