#ro0ted #OpNewblood What the blackhats dont want u to know: Memory Cloning + BE in Linux

Last tutorial we used Bulk Extractor for Windows this will be for Linux. – ro0ted


Open your terminal:

sudo apt-get -y install gcc g++ flex libewf-dev

gunzip bulk_extractor-1.5.5.tar.gz
tar xsvf ‘bulk_extractor-1.5.5.tar’

cd bulk_extractor-1.5.5 wget
gunzip hashdb-2.0.1.tar.gz
tar xsvf ‘hashdb-2.0.1.tar’

cd hashdb-2.0.1
sudo make install

cd bulk_extractor-1.5.5
sudo make install

to run type: bulk_extractor



And if you want a graphical interface instead of commands…
type: BEViewer

From here it’s very simple.
Click Tools>Run bulk_extractor:

This menu box will pop up:

Now don’t worry about the fancy settings we will get into that in another tutorial this is just a linux walk through:

You will need to create a memory dump I suggest using LiME

You can use any img file. For testing purposes if you are using a vm chances are you have this file:
Well you can throw this in Bulk Extractor although initrd isn’t your memory dump however you will get results:

 Okay I will use a simple utility to create a memory dump on a linux platform called Guymager this process is known as “memory cloning”

type: sudo apt-get install guymager
to run type: guymager


Right click acquire image:

Expert Witness Format is the best:

Select your output:


Then wait warning it will take a long time..:
You can also do a RAW Device scan:
Click RAW Device:




After the results are done which takes 3hrs minimum I will post the results. Check out my last tutorial on Bulk Extractor & Memory Dumping for a Windows Based machine here. Next tutorial I will show you how to do a memory dump of your Android. – ro0ted

