April 19, 2013
9:46 a.m.
On Fri, Apr 19, 2013 at 3:47 PM, Shraddha Kamat <sh2008ka@gmail.com> wrote:
I want to see live Virtual Addr. to Physical Addr. mappings for a process. is it possible to see such mappings ( for e.g. under /proc etc ..).
Hi... I am not really sure, but try to check Volatility tool. It is a forensic tool actually, and one of its functionality is able to check process mapping and dump the content. Hopefully I still recall about this thing correctly... -- regards, Mulyadi Santosa Freelance Linux trainer and consultant blog: the-hydra.blogspot.com training: mulyaditraining.blogspot.com