Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.
#MemoryForensics #IncidentResponse #DFIR #DigitalForensics
Chief of DIFR at SoteriaSec | SANS Institute Principal Instructor | Digital Forensics & Incident Response geek.