Skip to content

Releases: TazWake/linuxmemparser

Release v0.1.1

Choose a tag to compare

@TazWake TazWake released this 13 Dec 23:25
c3920bf

Function Update

This release adds functionality around timestamps, and allows you to specify the start time, which is then used as the base for the offset in the process structure. This release also resolves the issue of PID 0 and PID 1 being incorrectly identified.

Release v0.1.1

Changes

See CHANGELOG.md for detailed changes.

Installation

Download the binary for Linux x86_64:

# Download and verify
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1.1/linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.tar.gz
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1.1/linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.sha256

# Verify checksum
sha256sum -c linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.sha256

# Extract
tar xzf linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.tar.gz

# Make executable and move to PATH
chmod +x linuxmemparser
sudo mv linuxmemparser /usr/local/bin/

Checksums

SHA256: See attached .sha256 file for verification.

Release v0.1

Choose a tag to compare

@TazWake TazWake released this 12 Dec 22:53
f132266

Release v0.1

Changes

See CHANGELOG.md for detailed changes.

Installation

Download the binary for Linux x86_64:

# Download and verify
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1/linuxmemparser-0.1-x86_64-unknown-linux-gnu.tar.gz
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1/linuxmemparser-0.1-x86_64-unknown-linux-gnu.sha256

# Verify checksum
sha256sum -c linuxmemparser-0.1-x86_64-unknown-linux-gnu.sha256

# Extract
tar xzf linuxmemparser-0.1-x86_64-unknown-linux-gnu.tar.gz

# Make executable and move to PATH
chmod +x linuxmemparser
sudo mv linuxmemparser /usr/local/bin/

Checksums

SHA256: See attached .sha256 file for verification.

Second Beta Release

Choose a tag to compare

@TazWake TazWake released this 12 Dec 18:19
c61cf76

This version is starting to be functional. It should generate a list of processes identified in the memory image, in a pslist-like format. It will still be noisy and requires care to use. This version has updated how timestamps are shown - they are now an offset from the system boot time. There has been some improvement in how command line data is parsed, but this is still incomplete and potentially inaccurate.

Release v0.0.2.1B

Choose a tag to compare

@TazWake TazWake released this 12 Dec 21:01
2a50eb8

Release v0.0.2.1B

Changes

See CHANGELOG.md for detailed changes.

Installation

Download the binary for Linux x86_64:

# Download and verify
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.0.2.1B/linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.tar.gz
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.0.2.1B/linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.sha256

# Verify checksum
sha256sum -c linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.sha256

# Extract
tar xzf linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.tar.gz

# Make executable and move to PATH
chmod +x linuxmemparser
sudo mv linuxmemparser /usr/local/bin/

Checksums

SHA256: See attached .sha256 file for verification.

First Beta Release

Choose a tag to compare

@TazWake TazWake released this 12 Dec 17:59
e8c29db

This version is starting to be functional. It should generate a list of processes identified in the memory image, in a pslist-like format. It will still be noisy and requires care to use.

Initial Version - Pre-Alpha Release

Pre-release

Choose a tag to compare

@TazWake TazWake released this 11 Dec 00:05
180d343

Initial Version - POC only

This version is just a proof of concept to ensure the Rust file will compile. It is not yet functional, although it will try to find offsets.

There are still significant issues in how it uses the dwarf2json file to locate memory structures.

DO NOT USE THIS IN PRODUCTION ENVIRONMENTS and this file is not suitable for analysis work at this time.