Cisco-Talos / pyrebox

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU
https://talosintelligence.com/pyrebox
GNU General Public License v2.0
1.65k stars 249 forks source link

windows wintree wndscan #87

Closed Waterman178 closed 5 years ago

Waterman178 commented 5 years ago

Do these three plugins support win7x64? Why don't they work? QQ截图20190606161540

xabiugarte commented 5 years ago

Those 3 plugins are volatility plugins, and I don't see any reason why they should not work on win7x64. You may need to provide additional parameters to the commands.

Waterman178 commented 5 years ago

Those 3 plugins are volatility plugins, and I don't see any reason why they should not work on win7x64. You may need to provide additional parameters to the commands.

I have looked at the source but they don't need any additional parameters.

xabiugarte commented 5 years ago

I've tried to reproduce this problem but the plugins seem to work on my environment. Are you observing any additional errors? Are the rest of volatility plugins (e.g.: pslist) working? Any additional information you can provide would be useful.

xabiugarte commented 5 years ago

Correction: I managed to reproduce this if I run the commands on a system that is still booting up (i.e., when the KPCR / KDGB are ready, so that volatility can run but the system has not yet booted up)

xabiugarte commented 5 years ago

Closing due to lack of activity. Please reopen it if you are still having issues.