mquire: Linux memory forensics without debug symbols
mquire is a Linux memory forensics tool that can analyze kernel memory snapshots without relying on external debug symbols, by using BTF type data and kallsyms information already embedded inside the kernel itself.
[Read More]