Skip to content
@MemorySlice

MemorySlice

A modern, block-based, append-only forensic capture format for process memory — and the open-source ecosystem built around it.

Memory Slice (.msl)

Process-centric. Self-describing. Forensically sound.

A modern, block-based, append-only forensic capture format for process memory — and the open-source ecosystem built around it.


Why Memory Slice?

Classical memory forensics is system-centric: acquire the full physical address space, apply an OS profile, walk kernel structures. That model breaks down in containers, embedded targets, mobile platforms, and time-critical triage — exactly where modern incident response increasingly lives.

Memory Slice flips the paradigm to process-centric acquisition. A .msl capture is not just a virtual address space — it is a self-describing record of what was true about the process at acquisition time: module list with versions, file descriptors, region permissions, and network connections, all embedded as typed blocks.

Three properties make MSL useful for forensics rather than just convenient for dumping:

  • Epistemic honesty about TOCTOU. A 2-bit PageStateMap per region distinguishes Captured, Failed/Paged, and Unmapped pages — analysis tools never have to guess whether a zero page is real or an acquisition artifact.
  • BLAKE3 hash chain. Each block forward-hashes into the next, so any tampering with original acquisition data invalidates the chain. Fast enough to never bottleneck gigabit acquisition.
  • Zero-copy friendly. Strict 8-byte alignment throughout, so C/C++/Rust parsers can mmap() and go.

The full design rationale lives in memslice-spec.


The ecosystem

   ┌──────────────┐    ┌──────────────┐    ┌──────────────┐
   │  memslicer   │───▶│   .msl file  │───▶│   MemDiver   │
   │  (acquire)   │    │  (libmsl)    │    │  (analyze)   │
   └──────────────┘    └──────────────┘    └──────────────┘
Repository Role Language
memslice-spec Definitive binary format specification (current draft: 2026-03) —
memslicer Reference acquirer — Python, cross-platform (Linux/Windows/macOS) Python
memslicer-rs Reference acquirer — high-throughput Rust port Rust
libmsl Parsing library for embedding MSL support in third-party tools C / C++ / Rust
MemDiver Interactive workbench for identifying and analyzing data structures in .msl (and other) memory dumps — FastAPI + React, with an MCP server for AI-assisted analysis Python / TypeScript
memslice-samples Validated sample captures (compressed, partial-failure, multi-region) for parser conformance testing —

Getting started

  • Just want to look at memory? → start with MemDiver — pip install memdiver and load a sample.
  • Need to capture a process? → memslicer (Python) or memslicer-rs (Rust).
  • Building a tool that reads .msl? → libmsl and the spec.
  • Implementing your own parser? → memslice-spec plus memslice-samples for round-trip tests.

Research

Memory Slice and the differential / candidate-discovery techniques built on top of it are described in research currently under submission at IMF 2026. Citation will be updated post-review; an archival DOI on Zenodo will follow camera-ready.

Contributing

We welcome issues, PRs, and proposals for new Block Types in either the Semantic or Structural namespace. File against the relevant repo; cross-cutting design discussion belongs in memslice-spec.

License

Each repository ships under its own license — see individual LICENSE files. Most are Apache-2.0.

Popular repositories Loading

  1. memslice-spec memslice-spec Public

    The Memory Slice specification

    TeX 1 1

  2. memslicer memslicer Public

    A memory acquisition tool that captures process memory snapshots into the MSL (Memory Slice) binary format.

    Python 1 1

  3. MemDiver MemDiver Public

    Interactive platform for identifying and analyzing data structures in (process) memory dumps

    Python 1

  4. .github .github Public

  5. libmsl libmsl Public

    Rust

  6. memslicer-rs memslicer-rs Public

    Rust

Repositories

Showing 7 of 7 repositories
  • MemDiver Public

    Interactive platform for identifying and analyzing data structures in (process) memory dumps

    MemorySlice/MemDiver's past year of commit activity
    Python 1 Apache-2.0 0 0 0 Updated Sep 17, 2026
  • memslicer Public

    A memory acquisition tool that captures process memory snapshots into the MSL (Memory Slice) binary format.

    MemorySlice/memslicer's past year of commit activity
    Python 1 Apache-2.0 1 0 0 Updated Sep 14, 2026
  • memslice-spec Public

    The Memory Slice specification

    MemorySlice/memslice-spec's past year of commit activity
    TeX 1 Apache-2.0 1 0 1 Updated Jul 29, 2026
  • .github Public
    MemorySlice/.github's past year of commit activity
    0 Apache-2.0 0 0 0 Updated Jul 28, 2026
  • memslicer-rs Public
    MemorySlice/memslicer-rs's past year of commit activity
    Rust 0 Apache-2.0 0 0 0 Updated Mar 15, 2026
  • libmsl Public
    MemorySlice/libmsl's past year of commit activity
    Rust 0 Apache-2.0 0 0 0 Updated Mar 15, 2026
  • MemorySlice/memslice-samples's past year of commit activity
    0 Apache-2.0 0 0 0 Updated Mar 13, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Most used topics

Loading…