Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
mquire — Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info. | Kitploit
Tools/GitHubGitHub/trailofbits/mquire
OSINT (Open Source Intelligence)Memory ForensicsVulnerability AnalysisReverse EngineeringForensicsMalware AnalysisDigital ForensicsBinary AnalysisThreat IntelligenceLearning & EducationIncident Response
18484623 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
trailofbits/mquire

mquire

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

View RepositoryWebsite

mquire

mquire, a play on the memory and inquire words, is a memory querying tool inspired by osquery.

Key advantage: No external debug symbols needed

mquire can analyze Linux kernel memory snapshots without requiring external debug symbols.

Everything needed for analysis is already embedded in the memory dump itself. This means you can analyze:

  • Unknown or custom kernels you've never seen before
  • Any Linux distribution without preparation
  • Memory snapshots where external debug symbols are unavailable or lost

Requirements

Kernel version requirements:

  • BTF support: Kernel 4.18 or newer with BTF enabled (most modern distributions enable it by default)
  • Kallsyms support: Kernel 6.4 or newer (due to changes in scripts/kallsyms.c format)

How it works

mquire analyzes kernel memory by reading two types of information that are embedded in modern Linux kernels:

  1. Type information from BTF (BPF Type Format) - Describes the structure and layout of kernel data types. BTF data is parsed using the btfparse crate.
  2. Symbol information from Kallsyms - Provides the memory locations of kernel symbols (same data used by /proc/kallsyms)

By combining type information with symbol locations, mquire can find and read complex kernel data structures like:

  • Process memory mappings (using maple tree structures)
  • Cached file data (using XArray structures)
  • Kernel log messages

This makes it possible to extract files directly from the kernel's file cache, even if they've been deleted from disk.

Compatibility notes

The Kallsyms scanner depends on the data format from scripts/kallsyms.c in the kernel source. If future kernel versions change this format, the scanner heuristics may need updates.

Capabilities

Tables

mquire provides SQL tables to query different aspects of the system or the state of the tool itself.

mquire is not a database. Each query reconstructs kernel data structures by scanning memory and following pointers. There are no precomputed indexes or cached results: every table access is a traversal of kernel data. Use AS MATERIALIZED to avoid redundant scans (see Query Optimization), and provide constraints like task when querying per-process tables like task_open_files and memory_mappings to limit the scan to a single process.

Design principle: virtual addresses as join keys. Tables use virtual_address (the kernel address of the underlying data structure) as the canonical join key: not pid or other user-visible identifiers. This is intentional, because the same PID can appear multiple times across different discovery sources and root tasks, while a virtual address uniquely identifies a specific kernel object. Both the SQL tables and the underlying LinuxOperatingSystem API are built around this convention.

System information

  • os_version - Kernel version and architecture
  • system_info - Hostname and domain name
  • boot_time - System boot time
  • kallsyms - Kernel symbol addresses (same data as /proc/kallsyms)
  • dmesg - Kernel ring buffer messages (same data as dmesg command)

Process information

  • tasks - Running processes with command lines and binary paths. Each task is discovered via multiple independent sources, which is useful for rootkit detection. See Comparing task enumeration methods for rootkit detection and Deduplicated process list.
  • task_open_files - Files opened by each process (provide a task constraint for targeted analysis, or query all tasks at once)
  • memory_mappings - Memory regions mapped by each process (provide a task constraint for targeted analysis, or query all tasks at once)
  • task_capabilities - Linux capability sets (effective, permitted, inheritable, bounding, ambient) for a task. Requires a task constraint, so join it against tasks/processes (e.g. JOIN task_capabilities c ON c.task = p.virtual_address).
  • task_ptrace_flags - Decodes the ptrace field of a given task. Requires a task constraint.

Kernel modules

  • kernel_modules - Loaded kernel modules with metadata (name, state, version, parameters, taint flags)
  • kernel_module_mem_entries - The mem entries from a kernel module object. Requires a kernel_module constraint, so join it against kernel_modules (e.g. JOIN kernel_module_mem_entries r ON r.kernel_module = m.virtual_address).
  • ftrace_ops - A list of struct ftrace_ops nodes, walked from the ftrace_ops_list symbol by default. Constrain virtual_address to read a single node, or start_vaddr (optionally bounded by end_vaddr) to walk from an arbitrary node.

Network information

  • network_connections - Active network connections (TCP sockets)
  • network_interfaces - Network interfaces with IP addresses and MAC addresses

File system

  • syslog_file - System logs read from the kernel's file cache (works even if log files are deleted or unavailable, as long as they're cached in memory)

Debugging

  • mquire_diagnostics - Internal mquire logs showing analysis progress, warnings, and errors

Commands

mquire provides three main commands:

  • mquire shell - Start an interactive SQL shell to query memory snapshots
  • mquire query - Execute a single SQL query and output results (supports JSON or table format)
  • mquire command - Execute custom commands on memory snapshots (e.g., .task_tree, .system_version, .dump)

Dot Commands

mquire provides special commands prefixed with a dot (.) to distinguish them from SQL queries.

Built-in Commands

These commands work in the interactive shell and with mquire query:

  • .tables - List all available tables
  • .schema - Show schema for all tables
  • .schema <table> - Show schema for a specific table
  • .commands - List all available custom commands
  • .exit - Exit the interactive shell (shell only)

Custom Commands

These commands work in the interactive shell and with mquire command:

Use --help with any command to see available options and usage information. For example: .task_tree --help

.system_version

Display the operating system version information.

This is a convenience command equivalent to SELECT * FROM os_version, but with formatted output.

.task_tree

Display a hierarchical tree of running processes and threads, similar to the pstree command on Linux.

Options:

  • --show-threads - Include threads in addition to processes. When enabled, displays both TGID and TID for each entry.
  • --use-real-parent - Use the real_parent field instead of parent for building the tree structure. The real_parent field shows the original parent process before any reparenting (useful for tracking process creation chains even after parent processes exit).

Notes:

  • The format is [TGID TID] when showing threads, or [TGID] when threads are hidden. TGID (Thread Group ID) is what's commonly called PID. For main threads (where TGID == TID), both values will be the same.

.carve

Carve a region of virtual memory to disk. This command extracts raw memory content from a specific virtual address range using a given page table, useful for extracting process memory, heap contents, or other memory regions.

Arguments:

  • ROOT_PAGE_TABLE - The physical address of the root page table (hex string with optional 0x prefix). This determines the address space to use for translation.
  • VIRTUAL_ADDRESS - The virtual address to start carving from (hex string with optional 0x prefix).
  • SIZE - Number of bytes to carve.
  • DESTINATION_PATH - Output file path where the carved memory will be written.
Download Tool