On 07/05/2017 10:01 AM, Andrey Korolyov wrote:
The fourth/fifth points has very high likeness for the fact that the regular kernel debugging would not help at all and I hardly imagine myself spending few more days to manage firewire memory 'sniffer' to work, though this method has highest successful potential among other approaches, excluding (unavaiable due to pricing of the counterparting LA) memory interceptor. What could be a suggestion to move on with least effort at this point?
So you are after memory contents? Freeze DIMMS, turn off memory scrambling and flash firmware that dumps memory contents. In essence, cold boot attack.
Andrey