google / grr

GRR Rapid Response: remote live forensics for incident response
https://grr-doc.readthedocs.io/
Apache License 2.0
4.77k stars 762 forks source link

Pls help me with creating complete memory dump #926

Closed icepaule closed 3 years ago

icepaule commented 3 years ago

Hi team,

could please someone get me to the right direction on creating a complete mem-dump (for linux and windows) so I can further investigate with volatility and stuff? It seems I only find ways to dump single processes but not the complete memdump.

Thaanks a lot for you support and this great tool. ;-)

Cheers Marcus

max-vogler commented 3 years ago

GRR no longer supports complete, physical memory collection, because it created a variety of issues on the endpoints.

icepaule commented 3 years ago

Thanks Max . Sad to hear that. So closing th case.