elastic / elastic/roadmap

Memory dump Linux response action

Open
#197 0 comments 0 reactions 1 assignee Claimed by @raqueltabuyo View on GitHub
Component: Elastic Cloud Hosted Component: Elastic Cloud Serverless product-area:security
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**Value proposition**
Extend Elastic Security’s forensic and response capabilities to Linux endpoints by enabling remote process memory dump collection. This allows analysts to capture memory snapshots from specific Linux processes directly from the Response Console, facilitating rapid malware triage, memory-resident threat detection, and post-compromise investigation.

**Expected outcome**

- Introduce a new process dump response action for Linux endpoints.
- Support dumping a specific process’s memory.
- Collected dumps are transferred and stored securely within Elastic for further export (downloadable DMP file).

**Key user stories / use cases**

- As a SOC analyst, I want to capture a dump of a suspicious Linux process so I can analyze its memory for injected code or malicious payloads.
- As a forensic analyst, I want to correlate process dumps with related alerts or sessions to confirm in-memory malware behavior.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.