Live Linux forensics in a KVM based environment (part 1 memory) Posted by @charleypfaff on March 28, 2013 bash forensics kvm linux volatility +