Skip to content

Area 06

Memory Forensics

Some evidence only ever exists in RAM: fileless payloads, injected code, live network state and unlinked processes. This area covers acquisition with LiME and AVML, building Volatility 3 symbol tables for the exact kernel, and the plugins that matter.

Key artifacts

  • LiME
  • AVML
  • Volatility 3

Guides in this area

06 · Memory Forensics

Linux Memory Forensics with LiME, AVML and Volatility 3

Acquire Linux RAM with LiME or AVML, build Volatility 3 symbol tables with dwarf2json, and find hidden processes, rootkit modules and bash history in memory.

memory-forensicsvolatilitylime
All areas