Andrew Case

Results 84 comments of Andrew Case

> Sadly, I am also having the same issue using the latest SIFT-Workstation...with Rekall no longer being dev'ed and now this not working...I'm running out of options. What is the...

@gcmoreira My apologies for not getting to this sooner. This is very nice work. Is this something you would consider porting to Volatility 3? If so, you should consider our...

Can you please confirm that you are using the latest master checkout of Volatility from here (github)? Line 204 does not match your backtrace: https://github.com/volatilityfoundation/volatility/blob/master/volatility/dwarf.py#L204

@shehreyarahmedkohati (and others), please git pull and try to run Volatility with your profiles again. I made an update to dwarf.py to hopefully address everyone at once: https://github.com/volatilityfoundation/volatility/commit/7b3f52b66935879c625f72bfb3430d741fefc24b

It is not solved. I am working on it, but getting those new types to parse is being difficult.

@swepeba could you please elaborate on 'did not work', specifically could you answer these: 1) Did you do a git pull of the latest master branch? 2) You used --profile=Win10x64_19041...

Did you let kdbgscan run to completion or did you stop it after the first result? If you stopped it then please re-run and wait for full output and then...

Hey @JohCn, Is this a distro provided kernel? If so can you send the uname -a output and the profile you are using?