volatilityfoundation / volatility3

Volatility 3.0 development
http://volatilityfoundation.org/
Other
2.69k stars 460 forks source link

Add support for scanned tasks to various Linux plugins #924

Open eve-mem opened 1 year ago

eve-mem commented 1 year ago

A lot of the linux plugins start from a task struct and provide lots of extra information about the processes. e.g. envvars, lsof, sockstat, psaux.

It would be great to allow this functionality to task structs found by scanning too. However the question is how to allow actually the user to this.

github-actions[bot] commented 1 year ago

This issue is stale because it has been open for 200 days with no activity.

eve-mem commented 1 year ago

I've made no major progress on this yet. I still do think it's a useful feature to add. I'll work on a simple example and see if it works well before adding support for everything.

github-actions[bot] commented 7 months ago

This issue is stale because it has been open for 200 days with no activity.

ikelos commented 6 months ago

Removing the stale flag and bumping because this sounds like it might one day be a useful feature to have. I need to revisit that draft at some point...

github-actions[bot] commented 3 days ago

This issue is stale because it has been open for 200 days with no activity.

eve-mem commented 2 days ago

That makes 400 days stale.... But i do think one day this will be useful to do.

ikelos commented 2 days ago

Yep, happy to keep the idea here. We can probably add an "idea" flag and then prevent those going stale, it's just whether we'd ever come back and look at them again? 5:S

eve-mem commented 2 days ago

Yah could do. In some ways i appreciate the guilt trip of an idea going stale, reminds me to try and think about it again...

ikelos commented 2 days ago

Yeah, it's nice to have the nudge. Ok, I'll leave it as is then and we can just keep marking it as not stale until one day we forget and it drifts quietly into oblivion... 5;P