|
Project Information
Featured
Downloads
Links
|
Volatilitux is pretty much the equivalent of Volatility for Linux systems. Volatilitux supports the following architectures for physical memory dumps:
It supports the following commands:
It can easily be extended with new architectures, commands and classes. Volatilitux automatically detects kernel structure offsets within the memory dump, and can export its current configuration into a XML file. If it is unable to successfuly detect offsets, you can use the provided Loadable Kernel Module to generate a configuration file. Volatilitux has been tested with the following machines:
Please see this blog post for more details: http://www.segmentationfault.fr/projets/volatilitux-physical-memory-analysis-linux-systems/ |