teamdfir / sift

SIFT
MIT License
489 stars 67 forks source link

[SALTSTACK] - sudo cast install teamdfir/sift-saltstack Volatility #624

Open coinsan opened 8 months ago

coinsan commented 8 months ago

sudo ./cast install teamdfir/sift-saltstack Description: Ubuntu 22.04.4 LTS amd64

test|-sift-python-packages|-sift-python-packages_|-nop: __run_num: 290 sls__: sift.python-packages changes: {} comment: 'One or more requisite failed: sift.python-packages.volatility.sift-python-volatility-community-plugins, sift.python-packages.volatility.sift-python-volatility-plugins-firefoxhistory.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-autoruns.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-uninstallinfo.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-idxparser.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-editbox.py-absent, sift.python-packages.volatility.sift-python-volatility-sift-plugins, sift.python-packages.volatility.sift-python-volatility-mimikatz-plugin-update, sift.python-packages.volatility.sift-python-volatility-plugins-apihooksdeep.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-javarat.py-absent, sift.python-packages.volatility.sift-python-packages-volatility-malfind-yarascan-options2, sift.python-packages.volatility.sift-python-volatility-plugins-malfinddeep.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-ssdeepscan.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-pstotal.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-trustrecords.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-mimikatz.py-absent, sift.python-packages.volatility.sift-python-packages-volatility-malfind-yarascan-options1, sift.python-packages.volatility.sift-python-volatility-plugins-malprocfind.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-prefetch.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-openioc_scan.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-chromehistory.py-absent, sift.python-packages.volatility.sift-python-volatility-plugins-usnparser.py-absent' duration: 0.007 result: false start_time: '14:41:27.913622'

coinsan commented 8 months ago

saltstack.log

ekristen commented 8 months ago

This is due to a change with m2crypto. We have a fix inbound. Hopefully a fix out today.

ekristen commented 8 months ago

I just did a full install with the latest v2024.02.24 and everything installed as expected. Please give it a try.

coinsan commented 8 months ago

Installer hangs after this step (waited several minutes before cancelling the jobs) (tried twice)(second attempt included fresh ubuntu installation):

INFO[1984] state completed component=installer duration=2633.272 state=/tmp/awscli-exe-linux-x86_64.zip time_begin="09:55:21.428523" time_end="09:55:24.061798"

saltstack.log

ekristen commented 8 months ago

ok based on output, it's not actually hung, the tracking code lost track of where it was at due to the output. We might have to backout the aws cli change.

ekristen commented 8 months ago

v2024.02.25 is out, should resolve the apparent hang.