Linux memory forensics - memory capture with LiME and AVML

Описание к видео Linux memory forensics - memory capture with LiME and AVML

Linux Command Line tutorial for forensics - 43 - Linux memory forensics - memory capture with LiME and AVML

♥️ SUBSCRIBE for more videos: https://www.youtube.com/bluemonkey4n6...


Difficulty Level: advanced
Prerequisites: strong understanding of linux command line
strong understanding of partitions and file systems

In this video, we will look at capture memory on a Linux machine using LiME and AVML.


Video timeline
00:00 intro
00:55 AVML intro
01:43 AVML download
02:54 memory capture using AVML
06:01 AVML quick verification
07:15 LiME intro
08:14 LiME download
09:19 Target system recon to determine kernel version
09:49 LiME compile on exemplar system with same kernel version as target
13:31 LiME quick verification


To download the LiME source files: https://github.com/504ensicsLabs/LiME
To download the AVML executable file: https://github.com/microsoft/avml

⭕️ For other videos about the Linux command line, see other videos in this series:    • Linux Command Line tutorial  

Linux distro:
CAINE  linux (http://www.caine-live.net)

Virtualization software:
Virtual Box (http://virtualbox.org)


Icons made by freepik from @flaticon http://www.flaticon.com/authors/freepik

Icons made by Smashicons from http://www.flaticon.com/authors/smash...


This course was designed to provide information on how to use the command line environment in a Unix/Linux system to accomplish tasks such as imaging, data acquisition, and archiving.  This course covers the basics of Unix/Linux commands that allow users to view and edit text files, obtain hardware and system information, partitioning and formatting, process related commands, manipulating disks and partitions, imaging, archiving, logical acquisition, live system response, and basic networking.

This would be beneficial for folks who are interested in digital forensics, incidence response, system administration, ethical hacking, or just plain linux.  his course covers material for beginners as well as for advanced users. This course would also be helpful if you are considering taking the CompTIA Linux+ certification test.


#Linux #DFIR #memoryForensics

Комментарии

Информация по комментариям в разработке