Linux Memory Acquisition with LiME | HackerSploit Blue Team Training
Continuing our Blue Team Training series, in this video, @HackerSploit will cover the importance of memory acquisition using LiME. LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices. In this video, we’ll show how to build the LiME kernel object and how to dump Linux memory with LiME for analysis.
The full Blue Team Training series is available here.
Chapters:
0:00 Introduction
0:44 What We’ll Be Covering
1:00 Pre Requisites
1:53 What is Memory Acquisition?
3:58 Introduction to LiME
6:29 Learning Resources
6:39 Practical Demo
6:51 Making LiME
11:01 Load the Kernel Object
12:31 Locate the RAM Dump File
12:57 Conclusion
New to Linode? Get started here with a $100 credit!
Check out LiME on Github.
Watch Hackersploit’s Red Team Series.
Subscribe to get notified of new episodes as they come out.
#Linode #cybersecurity #hackersploit
Product: Linode, Hackersploit, LiME; @HackerSploit