user3486971
user3486971

Reputation: 1

How to get process list of running Linux VM using volatility?

How to run volatility directly on RAM of a running VM, without need to get memory dump first?

Upvotes: 0

Views: 314

Answers (1)

Alessandro De Vito
Alessandro De Vito

Reputation: 101

Volatility is not designed for analysis on live systems.

If you need to get VM's process list using a memory forensics framework and you're interested in live analysis of hypervisor, I suggest you to use Rekall:

VM discovery and introspection with Rekall

Upvotes: 1

Related Questions