Skip to main content

Free Shipping on Domestic Orders $75+

How to analyze RAM through Kali Linux Forensics mode

Views: 3.2K

View statistics:

Past 24 Hours:
5
Past 7 Days:
28
Past 30 Days:
105
All Time:
3,193
Comments: 2

2 comments on steps.

Completed: 1

1 person has marked this guide "completed." Will you be next?

Favorites: 0

No one has favorited (and subscribed to) this guide. Will you be the first?

Time Required: 2 minutes
Difficulty: Easy
Community-Contributed Guide

An awesome member of our community made this guide. It was not created by iFixit staff.

How to analyze RAM through Kali Linux Forensics mode

Introduction

Go to step 1 ↓

Much like how a memory analysis can be done on a hard drive, memory analysis can also be done on RAM modules. Because RAM is a volatile memory source, which means as soon as it is turned off it will loose data.

However, one of the cool things that can be done with memory analysis is that a user can recreate what was happening when an issue occurred by using the Volatility application.

    1. How to analyze RAM through Kali Linux Forensics mode, Plug in your Live Kali Linux USB: step 1, image 1 of 1
      • Plug in your Live Kali Linux USB into your computer and restart your PC.

      • Once your machine is finished restarting you should see Kali's Boot Loader.

      Ask FixBot

      Add Comment

      • Choose Live (forensic mode) from the list of options.

      • This will take you into the forensics mode, which contains the tools and packages needed to preform system forensic needs.

      Ask FixBot

      Add Comment

      • Press Ctrl + Alt + T to open the Terminal Interface.

      Ask FixBot

      Add Comment

      • Navigate to the Volatility directory with the command: cd /usr/share/volatility

      Ask FixBot

      Add Comment

      • Search for the RAM's profile with: python vol.py imageinfo -f=<location of image file>

      Ask FixBot

      Add Comment

Conclusion

Because Volatility is a Python script, you can enter the command python vol.py -h to gain additional information.

The most important thing you should take away from this guide is to remember to use this information responsibly. Obtaining unauthorized access to another's computer system or systems is illegal under the Computer Fraud & Abuse Act.

Please use the knowledge gained from this guide responsibly.

Cancel: I did not complete this guide.

One other person completed this guide.

Jacob Mehnert

Member since: 10/18/21

50,133 Reputation

52 Guides authored

Team

iFanatics Member of iFanatics

Community

70 Members

1,152 Guides authored

0 Guide Comments

Add Comment

View Statistics:

Past 24 Hours: 5

Past 7 Days: 28

Past 30 Days: 105

All Time: 3,193