GNU/Linux Memory Forensics: Is the Compromise Still Live?
Following the evidence in memory to determine what survived after an attack
Sep 3, 20269 min read1

Search for a command to run...

Series
The Forensic Trail is a practical digital forensics series exploring how systems store, hide, change, and leave behind digital evidence. From memory and disk artefacts to timestamps, file systems, boot records, and the techniques used to conceal data, each article examines the structures investigators rely on and how separate pieces of evidence can be analysed and connected to reconstruct what really happened.
Following the evidence in memory to determine what survived after an attack

Tracing a live Windows infection through volatile memory, from a suspicious process to injected code, persistence, and attacker intent.
