Closed S1ddh1 closed 7 months ago
Hi there, volatility3 doesn't yet support the ARM architecture (see #161) so it's not yet expected behaviour. 5;)
As to the issues with constructing the JSON file I suspect that dwarf2json is expecting an ELF file, rather than a DWARF one. I think you can wrap DWARF in the appropriate ELF format, but you might try handing in the .ko
or .o
file instead?
But yeah, at the moment, ARM and ARM64 support will need some development time since there's nothing in place yet. Happy to let @ilch1 try to help with the dwarf2json if he can?
This issue is stale because it has been open for 200 days with no activity.
This issue was closed because it has been inactive for 60 days since being marked as stale.
Describe the bug I'm trying to analyze a dump from an android emulator. I followed the steps described here : https://github.com/volatilityfoundation/volatility/wiki/Android
I don't get any good result with volatility2.6 so i give a shot with volatility3. It didn't work either. The following errors are produced
Context Volatility Version: volatility3 Framework 1.0.0-beta.1 Operating System: Ubuntu 20 Python Version: 3.8.2 Suspected Operating System: Android goldfish 3.4 armv7 The dump is in Lime format (https://github.com/504ensicsLabs/LiME) Command: python3 vol.py -f ~/ram.dd linux.pslist.PsList
To Reproduce The files and the dump that I used can be downloaded here : https://www.dropbox.com/s/7edntg68eo2eoxp/goldfish_dump_and_files.zip?dl=0
It's a zip file containing :
The following command was used on the dump.
I produced the json symbol file with dwarf2json on the system.map file from goldfish.
I've got an error if i try to use dwarf2json on the module.dwarf file
This file was compiled using the module.c code in volatility2.6 (tools/linux) and the following makefile
The symbols directory contains the following zip files :
book.zip comes from www.memoryanalysis.net, see below :
Expected behavior I downloaded samples from here https://www.memoryanalysis.net/amf. There is a linux ARM64 dump there and it works
Any clue ? Thanks