Linux Memory Forensics: Using mprotect() with PROT_NONE
In case you didn’t catch it on the Volatility Labs blog, I found an interesting bug that we’ve had in the framework since we’ve had Linux support. If you’ve had cases that involved Linux samples and plugins like linux_yarascan, linux_strings etc, you … Continue reading Linux Memory Forensics: Using mprotect() with PROT_NONE