Reading Ram Using Linux

  • list of all running processes
  • process information
  • command-line information
  • username passwords
  • Unencrypted data from an encrypted disk
  • Recently opened file which has been wiped from disk
  • keystrokes
  • network information
  • crypto keys and ton lot of more data.

So then How to read ram Data?

LiME ~ Linux Memory Extractor

yum install kernel-devel kernel-headers -y
git clone https://github.com/504ensicsLabs/LiME.git
cd LiMe/src
yum install make
yum groupinstall "Development tools"
yum install elfutils-libelf-devel
make
insmod ./lime-4.14.198-152.320.amzn2.x86_64.ko "path=./ramdata.mem format=raw"
cat ramdata.mem | strings | grep "x=5"

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store