Notifications
Clear all

MAC memory dump

12 Posts
11 Users
0 Reactions
10.7 K Views
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I will also agree with the above comments.

Unless I missed something or some messages were deleted, the original poster seems to be asking about dumping memory from a Mac, not performing analysis of a memory dump.

Where between the original post and the first response did the context change?


   
ReplyQuote
Beleka
(@beleka)
Eminent Member
Joined: 8 years ago
Posts: 29
 

https://ponderthebits.com/2017/02/osx-mac-memory-acquisition-and-analysis-using-osxpmem-and-volatility/

You can follow this guide to extract and create the profile associated with your Mac. I tried it on different distributions and builds, and it worked perfectly.

About analysis in my opinion, the best choice is extracting RAW memory from the AFF4 format rekall create, and analyze it with Volatility.

Regards


   
ReplyQuote
Page 2 / 2
Share: