Repository navigation
Releases: TazWake/linuxmemparser
Release list
Release v0.1.1
Function Update
This release adds functionality around timestamps, and allows you to specify the start time, which is then used as the base for the offset in the process structure. This release also resolves the issue of PID 0 and PID 1 being incorrectly identified.
Release v0.1.1
Changes
See CHANGELOG.md for detailed changes.
Installation
Download the binary for Linux x86_64:
# Download and verify
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1.1/linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.tar.gz
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1.1/linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.sha256
# Verify checksum
sha256sum -c linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.sha256
# Extract
tar xzf linuxmemparser-0.1.1-x86_64-unknown-linux-gnu.tar.gz
# Make executable and move to PATH
chmod +x linuxmemparser
sudo mv linuxmemparser /usr/local/bin/Checksums
SHA256: See attached .sha256 file for verification.
Release v0.1
Release v0.1
Changes
See CHANGELOG.md for detailed changes.
Installation
Download the binary for Linux x86_64:
# Download and verify
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1/linuxmemparser-0.1-x86_64-unknown-linux-gnu.tar.gz
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.1/linuxmemparser-0.1-x86_64-unknown-linux-gnu.sha256
# Verify checksum
sha256sum -c linuxmemparser-0.1-x86_64-unknown-linux-gnu.sha256
# Extract
tar xzf linuxmemparser-0.1-x86_64-unknown-linux-gnu.tar.gz
# Make executable and move to PATH
chmod +x linuxmemparser
sudo mv linuxmemparser /usr/local/bin/Checksums
SHA256: See attached .sha256 file for verification.
Second Beta Release
This version is starting to be functional. It should generate a list of processes identified in the memory image, in a pslist-like format. It will still be noisy and requires care to use. This version has updated how timestamps are shown - they are now an offset from the system boot time. There has been some improvement in how command line data is parsed, but this is still incomplete and potentially inaccurate.
Release v0.0.2.1B
Release v0.0.2.1B
Changes
See CHANGELOG.md for detailed changes.
Installation
Download the binary for Linux x86_64:
# Download and verify
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.0.2.1B/linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.tar.gz
wget https://github.com/TazWake/linuxmemparser/releases/download/v0.0.2.1B/linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.sha256
# Verify checksum
sha256sum -c linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.sha256
# Extract
tar xzf linuxmemparser-0.0.2.1B-x86_64-unknown-linux-gnu.tar.gz
# Make executable and move to PATH
chmod +x linuxmemparser
sudo mv linuxmemparser /usr/local/bin/Checksums
SHA256: See attached .sha256 file for verification.
First Beta Release
This version is starting to be functional. It should generate a list of processes identified in the memory image, in a pslist-like format. It will still be noisy and requires care to use.
Initial Version - Pre-Alpha Release
Initial Version - POC only
This version is just a proof of concept to ensure the Rust file will compile. It is not yet functional, although it will try to find offsets.
There are still significant issues in how it uses the dwarf2json file to locate memory structures.
DO NOT USE THIS IN PRODUCTION ENVIRONMENTS and this file is not suitable for analysis work at this time.