s3eurecom retweetledi

You want to dump the physical memory of a Linux system but can't load a kernel driver or use /proc/kcore? Try Lemon, a CO-RE eBPF program that dumps the entire physical memory in LiME format. Developed by Sudharsun Lakshmi Narasimhan and me at @s3eurecom
github.com/eurecom-s3/lem…
English












