Closed xorya1 closed 1 year ago
Hi there,
Volatility doesn't come with every symbol table necessary for every OS because there are too many and because new ones are coming out all the time. Luckily, Microsoft provides files for Windows that can be used to generate symbols, volatility found one of those and tried to go out to the internet to get it and process it, but couldn't.
If you can't provide volatility and internet connection, then you can download the pdb file from the URL mentioned in the first output and then processing it with the pdbconv.py
tool using -f
or on a machine with the internet you can run pdbconv
with the parameters mentioned in the second output (following the instructions at: https://volatility3.readthedocs.io/en/latest/symbol-tables.html#windows-symbol-tables ). Either of those methods should generated a JSON file, that can then be put into your symbols directory (typically volatility3/symbols
, although this can be specified for vol.py
by using -s
).
Hopefully that answers your question and gets you up and running. I'll mark this as a question and probably close it at some point in the future. If you have more questions feel free to put them on here, or if this has been closed you could try our slack server at https://www.volatilityfoundation.org/slack.
hi everyone, I'm pretty sure this is a total beginner question but I can't seem to find a solution, I downloaded the volatilty3 by cloning from GitHub, and tried to run the "
python3 vol.py -f dump_practice.dmp [windows.info]
" and I get the following error"no clue how to fix it, I also ran this command :
python3 vol.py -v -f dump_practice.dmp windows.info
and this is the result i got if that helps in any way
also, is windows.info the equivalent for imageinfo plugin? and thank you.