ufrisk / MemProcFS

MemProcFS
GNU Affero General Public License v3.0
2.8k stars 352 forks source link

Some Windows 7 memory images cannot analyze dst ip and dst port. #283

Open Tokeii0 opened 2 months ago

Tokeii0 commented 2 months ago

============================== MemProcFS ==============================

[FORENSIC] FC_VIRTMEM_SCAN: INIT TOTAL: ranges=5193, bytes=df1c2000 [INFODB] INIT: SUCCESS: va=0xfffff880018f1000 [FORENSIC] FC_VIRTMEM_SCAN: FINISH [FORENSIC] INIT COMPLETED : time=4s

"M:\sys\net\netstat-v.txt" image

ufrisk commented 2 months ago

MemProcFS Windows 7 support isn't top notch unfortunately. I created this tool around 2018 and onwards and Windows 7 was never a big focus since it was quite old already by then.

I'll look into why this is missing though. Maybe there is something I can do about it.

Thanks for letting me know.