Ever come across a file running on a Linux box that was deleted from the disk? Did you know you can likely use DD to recover the file without any non-standard tools?
29
626
21
2,861
Replying to @ippsec @DfirNotes
You can also just “cp /proc/<pid>/exe /some/new/path”

Mar 14, 2022 · 12:04 AM UTC

3
9
98
Can also do a hash on the running binary this way as well even if deleted: sha1sum /proc/<pid>/exe
1
17
This doesn't work with python files