forensenellanebbia/volatility-profiles
GitHub: forensenellanebbia/volatility-profiles
为 Volatility 2 和 3 预构建的 Linux 内存取证配置文件集合,附带构建指南与各发行版资源链接。
Stars: 10 | Forks: 1
# volatility-profiles
我的博客文章 *为 Volatility 2 和 3 构建 Linux 配置文件*:
https://forensenellanebbia.blogspot.com/2021/02/building-profile-for-volatility-2-and-3.html
将配置文件复制到:
- Volatility 2: ~/volatility/volatility/plugins/overlays/**linux**/
- Volatility 3: ~/volatility3/volatility3/symbols/**linux**/
## 有用资源
**Red Hat Enterprise Linux (RHEL)**
* /pub/redhat/linux/enterprise: http://ftp.redhat.com/pub/redhat/linux/enterprise/
* 下载 Red Hat Enterprise Linux: https://access.redhat.com/downloads
* Red Hat 软件包: https://access.redhat.com/downloads/content/package-browser
* 激活密钥: https://console.redhat.com/settings/connector/activation-keys
* 如何使用激活密钥将系统注册到 Red Hat Subscription Management?: https://access.redhat.com/solutions/3341191
* 如何安装特定内核版本?: https://access.redhat.com/solutions/134403
* 如何为 RHEL 系统下载或安装内核 debuginfo 软件包?: https://access.redhat.com/solutions/9907
注册您的安装程序以便从 redhat repo 安装软件包:
安装这些软件包:
**CentOS**
* http://mirror.centos.org/centos/7/updates/x86_64/Packages/
* http://debuginfo.centos.org/7/x86_64/
**Fedora**
* https://kojipkgs.fedoraproject.org/packages/kernel/
**SUSE Linux Enterprise Server (SLE)**
* 下载试用版 ISO: https://www.suse.com/download/sles/
* 申请试用代码: https://scc.suse.com/products/2140
**libdwarf/dwarfdump**
* https://www.prevanders.net/dwarf.html#releases
标签:CentOS, DNS解析, DWARF, dwarfdump, Fedora, JARM, Linux Profile, PB级数据处理, Profile生成, RHEL, SUSE, Volatility 2, Volatility 3, 云资产清单, 内存分析, 内存转储分析, 内核调试, 安全渗透, 安全运维, 库, 应急响应, 开源项目, 数字取证, 系统符号表, 自动化脚本, 逆向工具, 逆向工程