Memory Acquisition ...
 
Notifications
Clear all

Memory Acquisition on Mac m1

2 Posts
2 Users
1 Reactions
3,481 Views
Vesalius
(@vesalius)
Estimable Member
Joined: 9 years ago
Posts: 66
Topic starter  

Hi all,

How do I dump memory (ram) on mac m1 chips. What is the best way to do this? I want to analyse a specific process while it's running live in RAM. I'm finding it quite difficult to do reversing or forensics on these newer ARM64 chip macs.

LLDB is just gives me the following error:

attach 52548

error: attach failed: Connection shut down by remote side while waiting for reply to initial handshake packet

I even tried running it as sudo, and I gave terminal full disk access.

Also when it comes to reverse engineering the application it self and debugging, what tool is the best when it comes to live debugging and disassembling?

When trying to debug using ghidra using LLDB locally in-vm it's just stuck at 0% and never fully loads.

I'm facing blockers every step of the way doing forensics on these newer M1 😅

I'm on an a security assessment for an Mac M1 based thick-client application 🙂

I'm new to doing this on macs so any input, ideas, and tips for this newer OS would be appreciated. 


   
Quote
(@dandaman_24)
Estimable Member
Joined: 11 years ago
Posts: 172
 

Surge offers most support for Mac RAM capture

https://www.volexity.com/products-overview/surge/


   
Vesalius reacted
ReplyQuote
Share: