lcamtuf-memfetch

Process memory dumper

Utility to dump process memory of running processes on Linux systems.

Memfetch is a simple utility to dump all memory of a running process, either immediately or when a fault condition is discovered. It is an attractive alternative to the vastly inferior search capabilities of many debuggers and tracers - and a convenient way to grab "screenshots" from many types of text-based interactive utilities.

GitHub

40 stars
5 watching
14 forks
Language: C
last commit: over 8 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
mobileforensicsresearch/memTool to dump memory from Android devices66
marcosd4h/memhunterAutomated endpoint sensor tool to detect memory-resident malware without requiring memory dumps378
theupbeat/lfetchA C program that fetches and displays Linux system information4
rek7/mxtractAnalyzes and dumps memory to extract sensitive information from running processes582
espressocake/ppldump_bofA tool for dumping the memory contents of a protected process on Windows136
rachelambda/mfetchA lightweight shell script for fetching system information29
trainr3kt/memreader_bofA tool that searches and extracts specific strings from another process's memory41
kost/memdumpA tool to extract and display the contents of a system's physical memory12
evild3ad/memprocfs-analyzerAutomated tool for forensic analysis of Windows memory dumps555
microsoft/clrmdA library for introspecting processes and dumps.1,063
xforcered/credbanditA proof-of-concept tool for dumping the memory of a process and sending it back through a custom communication channel.233
mehrankmlf/easycryptoAn iOS app demonstrating Clean Architecture and MVVM with SwiftUI and Combine framework80
myriadbits/mxfinspectTool to visually inspect and analyze the internal structure of MXF files39
rmccorm4/pokefetchA command-line tool that scrapes Pokémon information and displays it in a formatted output.49
yardenshafir/mitigationflagsclitoolPrints mitigation policy information for processes in a memory dump file.46