Closed cartel0x27 closed 7 years ago
Any chance you can upload the ntoskrnl.exe file from that system's disk somewhere and send a link? It looks like the object header cookie value is not being found (something new that's required for Windows 10 pool tag scanning).
OK, your file looks fine...the signature we want to locate is in there...so there must be another issue. Have you installed the distorm3 python module? This is required for Windows 8 and above. For more info on that, see:
https://github.com/volatilityfoundation/volatility/wiki/Windows-8-2012 and https://github.com/volatilityfoundation/volatility/wiki/Installation#dependencies
Let me know if you still have issues after that.
Thanks, but I already had the distorm3 python module installed.
Any other ideas?
@pnegry sorry for the delay. We've fixed a ton of Windows 10 related issues over the past couple weeks. Would you mind updating to the latest master branch and trying again?
I'm going to close out this issue, let me know if you're able to test in the coming days and if the existing fixes for Win10 doesn't help, we can reopen and take a look.
Hey there, I'm having some issues running Volatility against a crash dump from win10 enterprise build 1511.
My steps:
Physical Memory Description: Number of runs: 7 FileOffset Start Address Length 00002000 00001000 00057000 00059000 00059000 00044000 0009d000 00100000 00203000 002a0000 00307000 d099d000 d0c3d000 d0ea6000 09b8f000 da7cc000 dcfff000 00001000 da7cd000 100000000 2f9de0000 3d45ac000 3f9ddf000
$ $ vol.py netscan -f ./MEMORY.DMP --profile=Win10x64 Volatility Foundation Volatility Framework 2.5 Offset(P) Proto Local Address Foreign Address State Pid Owner Created Traceback (most recent call last): File "/usr/local/bin/vol.py", line 4, in
import('pkg_resources').run_script('volatility==2.5', 'vol.py')
File "/usr/local/lib/python2.7/dist-packages/pkg_resources/init.py", line 735, in run_script
self.require(requires)[0].run_script(script_name, ns)
File "/usr/local/lib/python2.7/dist-packages/pkg_resources/init.py", line 1652, in run_script
exec(code, namespace, namespace)
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/EGG-INFO/scripts/vol.py", line 192, in
main()
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/EGG-INFO/scripts/vol.py", line 183, in main
command.execute()
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/commands.py", line 145, in execute
func(outfd, data)
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/plugins/netscan.py", line 269, in render_text
for net_object, proto, laddr, lport, raddr, rport, state in data:
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/plugins/netscan.py", line 212, in calculate
for objct in self.scan_results(addr_space):
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/poolscan.py", line 213, in scan
cookie = obj.VolMagic(space).ObHeaderCookie.v()
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/plugins/overlays/windows/win10.py", line 205, in v
return self.get_best_suggestion()
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/obj.py", line 818, in get_best_suggestion
for val in self.get_suggestions():
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/plugins/overlays/windows/win10.py", line 212, in get_suggestions
for x in self.generate_suggestions():
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/plugins/overlays/windows/win10.py", line 217, in generate_suggestions
store.findcookie(self.obj_vm)
File "/usr/local/lib/python2.7/dist-packages/volatility-2.5-py2.7.egg/volatility/plugins/overlays/windows/win10.py", line 131, in findcookie
nt_mod = list(kdbg.modules())[0]
IndexError: list index out of range
$ vol.py pslist -f ./MEMORY.DMP --profile=Win10x64 Volatility Foundation Volatility Framework 2.5 Offset(V) Name PID PPID Thds Hnds Sess Wow64 Start Exit
(just returns having printed nothing)