mquire: Linux memory forensics without external dependencies
blog.trailofbits.com | blog | #open-source | #incident-response | #linux | #memory-forensics | #kernel | #tool-release | #trail-of-bits | #btf | #digital-forensics
Summary
Trail of Bits open-sourced mquire, which analyzes Linux memory dumps without external debug symbols by extracting BTF type information and symbol addresses directly from the dump itself.
- Published
- Collected
Skip to content