Hello, I am having trouble running the windows and wintree plugin in Volatility 2.6 ( installed from http://downloads.volatilityfoundation.org/releases/2.6/volatility_2.6_lin64_standalone.zip). When I try to run either one of the plugins, nothing is returned. I know there are windows present in RAM due the output from the plugins deskscan and screenshot. See sample output below
Empty Output from Windows and Wintree Pluginsvol2.py -f myMem.dd --profile=Win7SP1x86 windows
Output
Volatility Foundation Volatility Framework 2.6
vol2.py -f myMem.dd --profile=Win7SP1x86 wintree
Volatility Foundation Volatility Framework 2.6
I wasn't certain which windows 7 profile to use, but I tried all three that are available for x86, which includes Win7SP0x86, Win7SP1x86, Win7SP1x86_23418, and they all had the same output. Am I missing an argument when using these plugins or it is something else? Also, are there plugin equivalents in Volatility 3 for windows and wintree? Any help would be greatly appreciated. Thank you!
Hello, I am having trouble running the
windows
andwintree
plugin in Volatility 2.6 ( installed from http://downloads.volatilityfoundation.org/releases/2.6/volatility_2.6_lin64_standalone.zip). When I try to run either one of the plugins, nothing is returned. I know there are windows present in RAM due the output from the pluginsdeskscan
andscreenshot
. See sample output belowvol2.py -f myMem.dd --profile=Win7SP1x86 deskscan
Output snippetvol2.py -f myMem.dd --profile=Win7SP1x86 screenshot -D ./screenshots/
Output snippet (one image)Empty Output from Windows and Wintree Plugins
vol2.py -f myMem.dd --profile=Win7SP1x86 windows
Outputvol2.py -f myMem.dd --profile=Win7SP1x86 wintree
I wasn't certain which windows 7 profile to use, but I tried all three that are available for x86, which includes Win7SP0x86, Win7SP1x86, Win7SP1x86_23418, and they all had the same output. Am I missing an argument when using these plugins or it is something else? Also, are there plugin equivalents in Volatility 3 for windows and wintree? Any help would be greatly appreciated. Thank you!