using process_vm_readv (2) and process_vm_writev (2); • inspect processes using kcmp
NAME process-keyring