Memory dump Linux response action
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
**Value proposition**
Extend Elastic Security’s forensic and response capabilities to Linux endpoints by enabling remote process memory dump collection. This allows analysts to capture memory snapshots from specific Linux processes directly from the Response Console, facilitating rapid malware triage, memory-resident threat detection, and post-compromise investigation.
**Expected outcome**
- Introduce a new process dump response action for Linux endpoints.
- Support dumping a specific process’s memory.
- Collected dumps are transferred and stored securely within Elastic for further export (downloadable DMP file).
**Key user stories / use cases**
- As a SOC analyst, I want to capture a dump of a suspicious Linux process so I can analyze its memory for injected code or malicious payloads.
- As a forensic analyst, I want to correlate process dumps with related alerts or sessions to confirm in-memory malware behavior.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.