Skip to content

Glossary

LiME (Linux Memory Extractor)

LiME is a loadable Linux kernel module that dumps physical memory to a file or a TCP socket for later analysis with Volatility or other tools.

LiME, the Linux Memory Extractor, is an open source loadable kernel module (github.com/504ensicsLabs/LiME) that acquires a copy of physical memory from a running Linux or Android system. Because it runs inside the kernel, it can read RAM directly without relying on /dev/mem or /proc/kcore, which are often restricted on modern distributions.

The module is configured through parameters passed to insmod. path is either a file on external media or tcp:<port> to stream the image to an analyst workstation, and format selects lime (ranges prefixed with address headers, the preferred format for Volatility), raw or padded.

insmod lime-$(uname -r).ko "path=tcp:4444 format=lime"

The main operational constraint is that a kernel module must match the running kernel version and configuration. You have to compile LiME against the correct kernel headers ahead of time, on a trusted build system, and systems enforcing module signatures may refuse to load it. Loading a module also modifies kernel state, so record it in your notes. Userland alternatives such as AVML avoid the build step. See Linux memory forensics with LiME and Volatility.