LiME Logo

LiME

0
Free
Visit Website

LiME (Linux Memory Extractor) is a Loadable Kernel Module (LKM) that enables volatile memory acquisition from Linux and Linux-based devices, including Android. It is the first tool to allow full memory captures on Android devices, minimizing user-kernel space interaction for more forensically sound captures. Features include full Android memory acquisition, acquisition over network interface, minimal process footprint, and hash of dumped memory. Usage involves loading the module using the insmod command with specified arguments like path, format, and optional parameters like digest and dio.

FEATURES

ALTERNATIVES

MalConfScan is a Volatility plugin for extracting configuration data of known malware and analyzing memory images.

Advanced computer forensics software with efficient features.

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

A tool for extracting files from packet capture files with ease of use and extensibility for Python developers.

A utility for recovering deleted files from ext3 or ext4 partitions.

XMLStarlet offers a suite of command line utilities for manipulating and querying XML documents.

Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.

mac_apt is a versatile DFIR tool for processing Mac and iOS images, offering extensive artifact extraction capabilities and cross-platform support.