Closed dell224 closed 7 months ago
I think there is some confusion here. "Full process memory dumps" (procmemdump) are not the same thing as a full system dump of the vm memory which is what is required for volatility analysis.
The full process memory dump submission option causes each process to be dumped in full which is displayed in the "Process Memory" tab:
For volatility analysis I am not an expert as this is not part of cape that I use. However, the full system dumps that are required for volatility are enabled in cuckoo.conf
as follows:
# Enable creation of memory dump of the analysis machine before shutting
# down. Even if turned off, this functionality can also be enabled at
# submission. Currently available for: VirtualBox and libvirt modules (KVM).
memory_dump = on
Then the configuration of volatility is done in memory.conf
.
what volatility version do you use? as you might see in errors there is 2 things, vol is not installed msg and render error as it can't import due to not installed or bad version
Hi doomedraven,
It is volatility version 2.4.2.
I attempted to run the command suggested in the error pip3 install volatility3 -U
, and this is the result:
Defaulting to user installation because normal site-packages is not writeable
Requirement already satisfied: volatility3 in /usr/local/lib/python3.10/dist-packages (2.4.2)
Requirement already satisfied: pefile>=2017.8.1 in /usr/local/lib/python3.10/dist-packages (from volatility3) (2022.5.30)
Requirement already satisfied: future in /usr/lib/python3/dist-packages (from pefile>=2017.8.1->volatility3) (0.18.2)
somehow i missed that, you can't install package with pip if you using poetry
, you need to install it with poetry run pip install volatility3
About accounts on capesandbox.com
This is open source and you are getting free support so be friendly!
Prerequisites
Please answer the following questions for yourself before submitting an issue.
custom/conf/
Expected Behavior
Memory analysis successfully performed on the submitted samples using volatility3.
Current Behavior
The analysis report currently does not generate process memory and process dumps report despite procmemdump=1.
Failure Information (for bugs)
From journalctl -u cape.service, I can see 1 (one) missed dependencies and 1 (one) error pertaining to JsonRenderer.
Steps to Reproduce
Please provide detailed steps for reproducing the issue.
Context
Please provide any relevant information about your setup. This is important in case the issue is not reproducible except for under certain conditions. Operating system version, bitness, installed software versions, test sample details/hash/binary (if applicable).
$ git log \| head -n1
to find outcustom/conf/Processing.conf
custom/conf/Reporting.conf
Failure Logs
Please include any relevant log snippets or files here.
process.log