Notifications
Clear all
14/07/2018 12:00 pm
I will also agree with the above comments.
Unless I missed something or some messages were deleted, the original poster seems to be asking about dumping memory from a Mac, not performing analysis of a memory dump.
Where between the original post and the first response did the context change?
13/09/2018 1:11 pm
https://
You can follow this guide to extract and create the profile associated with your Mac. I tried it on different distributions and builds, and it worked perfectly.
About analysis in my opinion, the best choice is extracting RAW memory from the AFF4 format rekall create, and analyze it with Volatility.
Regards
Page 2 / 2
Prev