INTEL_REPORT
Trail of Bits — Security engineering · published 2/25/2026, 12:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
mquire: Linux memory forensics without external dependencies If you’ve ever done Linux memory forensics, you know the frustration: without debug symbols that match the exact kernel version, you’re stuck. These symbols aren’t typically installed on production systems and must be sourced from external repositories, which quickly become outdated when systems receive updates. If you’ve ever tried to analyze a memory dump only to discover that no one has published symbols for tha…
https://blog.trailofbits.com/2026/02/25/mquire-linux-memory-forensics-without-external-dependencies
sha256:7bf091c59d6c9afd5367f346205c419138b7e0534fc0f7726d4c7d6a6fc14ca1
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| dump.raw |
| Open → |