- Home
- Security Operations
- Digital Forensics and Incident Response
- AVML (Acquire Volatile Memory for Linux)

AVML (Acquire Volatile Memory for Linux)
A portable Rust-based tool for acquiring volatile memory from Linux systems without requiring prior knowledge of the target OS distribution or kernel.

AVML (Acquire Volatile Memory for Linux)
A portable Rust-based tool for acquiring volatile memory from Linux systems without requiring prior knowledge of the target OS distribution or kernel.
AVML (Acquire Volatile Memory for Linux) Description
AVML (Acquire Volatile Memory for Linux) is a portable volatile memory acquisition tool designed for Linux systems. Written in Rust as an X86_64 userland application, it functions as a static binary that can acquire memory without requiring prior knowledge of the target operating system distribution or kernel version. The tool operates by accessing memory through multiple sources including /dev/crash, /proc/kcore, and /dev/mem. When no specific memory source is specified, AVML automatically iterates through available sources to identify a functional option. It supports saving acquired memory images to external locations via Azure Blob Store or HTTP PUT methods. Key capabilities include automatic retry functionality with exponential backoff for network upload issues, optional page-level compression using Snappy algorithm, and compatibility with LiME output format when compression is not enabled. The tool requires no on-target compilation or system fingerprinting. AVML has been tested across multiple Linux distributions including Ubuntu (versions 12.04 through 22.04), CentOS (6.5 through 7.9), RHEL (6.7 through 9.0), and Debian (versions 8, 9, and 10). The tool cannot function when the kernel_lockdown feature is enabled on the target system.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.