Mac os x dump process memory
Mac's very odd combinations of translation requirements is one of the stranger things we have encountered during memory forensics research and required a team effort to get all the details and possibilities sorted and tested.
Posted by Andrew Case at No comments: Newer Post Older Post Home. Subscribe to: Post Comments Atom. It made me happy that I could write a reasonable first approximation of a vmmap clone in ish lines of Rust!
How do you read the memory maps of a Mac process?
My Rust program did what I hoped — it runs in like 80ms or something, about 15x faster than vmmap. For any dynamically linked libraries including a Ruby library, which I need the address and filename of!!