{"repo":"microsoft/avml","free":true,"listed":false,"github":"https://github.com/microsoft/avml","clone":"git clone https://github.com/microsoft/avml.git","description":"AVML - Acquire Volatile Memory for Linux","language":"Rust","stars":1118,"topics":["rust","memory-forensics","linux-security"],"license":"MIT","category":"api-integrations-sdks","readme_excerpt":"AVML (Acquire Volatile Memory for Linux) Summary A portable volatile memory acquisition tool for Linux. AVML is an X86\\ 64 userland volatile memory acquisition tool written in Rust, intended to be deployed as a static binary. AVML can be used to acquire memory without knowing the target OS distribution or kernel a priori. No on-target compilation or fingerprinting is needed. Features Save recorded images to external locations via Azure Blob Store or HTTP PUT Azure Blob Storage uploads retry transient failures via the Azure SDK's default exponential backoff policy (8 attempts, capped at one minute total elapsed). Optional page level compression using Snappy. Uses LiME output format (when not using compression). Memory Sources /dev/crash /proc/kcore /dev/mem If the memory source is not specified on the commandline, AVML will iterate over the memory sources to find a functional source. NOTE: If the kernel feature kernel\\ lockdown is enabled, AVML will not be able to acquire memory. Tested Distributions Ubuntu: 12.04, 14.04, 16.04, 18.04, 18.10, 19.04, 19.10, 20.04, 21.04, 22.04 Centos: 6.5, 6.6, 6.7, 6.8, 6.9, 6.10, 7.0, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.9 RHEL: 6.7, 6.8, 6.9, 7.0, 7.2, 7.3, 7.4, 7.5, 7.7, 8.5, 9.0 Debian: 8, 9, 10, 11, 12 Oracle Linux: 6.8, 6.9, 6.10, 7.3, 7.4, 7.5, 7.6, 7.9, 8.5, 9.0 CBL-Mariner: 1.0, 2.0 Subcommands avml is a single binary with subcommands. Each subcommand is gated by a Cargo feature so a minimal build only includes the capability you need: Sub","default_branch":null,"files":null,"tree":[],"storefront":"/r/microsoft","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/microsoft/avml/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}