Skip to main content

Linux memory snapshots

mquire

Memory-forensics tool that queries Linux kernel snapshots over SQL, using BTF and kallsyms embedded in the dump so no external debug symbols are needed.

View on GitHub trailofbits/mquire

Best for

Incident response and forensics against unknown or custom kernels where shipping matching debug symbols is impractical.

Surface

Linux memory snapshots

Catalog group

Inspect operating systems and endpoint surfaces

Repository

trailofbits/mquire

Related tools · Inspect operating systems and endpoint surfaces