LiME (Linux Memory Extractor)
Definition
A loadable kernel module that acquires physical memory from Linux, macOS, and Android systems. It maps the physical address space and either writes the image to a file or streams it over a TCP connection to a remote collection host. Requires root privileges and a module compiled for the target kernel version.
- Type
- Loadable kernel module
- Platforms
- Linux, macOS, Android
- Output
- Raw memory image to file or TCP stream
- Requirement
- Root privileges and a build matched to the target kernel
Common questions
Why must LiME be compiled for the exact target kernel version?+
The module hooks kernel memory structures directly, so a version mismatch can fail to load or, worse, crash the system, an unacceptable risk when the target machine is live evidence.
What is the advantage of streaming the image over TCP instead of writing to disk?+
Writing to the suspect disk risks overwriting evidence and changes the very data being preserved. Streaming to a remote host keeps the acquisition read only on the target.
Related terms
- Order of Volatility
- The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
- Physical Memory Image
- A byte-for-byte copy of all installed RAM on a running system, acquired at the hardware or kernel level. Contains all data structures,...
- Process Injection
- A technique used by malware and attackers to execute code inside the address space of a legitimate running process. Common methods include...
- Reflective DLL Loading
- A technique that loads a Windows DLL directly from memory without registering it with the OS loader. The DLL resolves its own...
- Volatility Framework
- An open-source memory forensics framework written in Python. It parses raw memory images using OS-specific symbol information to reconstruct kernel data structures...