Forensics
Jump to navigation
Jump to search
Forensics
Linux
Tools to extract entire system RAM to a file
- LiME (Linux Memory Extractor)
A Loadable Kernel Module (LKM) which allows for volatile memory acquisition from Linux and Linux-based devices, such as Android. This makes LiME unique as it is the first tool that allows for full memory captures on Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisition.- Works as a kernel module
- Compiles on Linux and Android