el Tedward
November 26th, 2009, 05:00 AM
I was wondering what tools people have heard of that can be used for grabbing volatile memory off of a live linux system. I've read about some of the cold boot attacks, but I'm looking more for something that I could use without having to reboot or physically pull the RAM out of a system.
The instructor for my forensics class (not that I would ever go to an internet forum for help on an assignment..), said that I could use dd to grab what's stored in my RAM, but I'm still a bit of a linux n00b and I haven't really been able to figure out what sort of syntax I would use to do that..
So, if someone could explain to me how to do this with dd, or mention any tools available for volatile memory "recovery" made for linux systems(it's okay if it's not free, as long it's not designed to work with windowz..) it would be extremely helpful.
The instructor for my forensics class (not that I would ever go to an internet forum for help on an assignment..), said that I could use dd to grab what's stored in my RAM, but I'm still a bit of a linux n00b and I haven't really been able to figure out what sort of syntax I would use to do that..
So, if someone could explain to me how to do this with dd, or mention any tools available for volatile memory "recovery" made for linux systems(it's okay if it's not free, as long it's not designed to work with windowz..) it would be extremely helpful.