volatility icon indicating copy to clipboard operation
volatility copied to clipboard

Volatility not working with windows Livekd memory dump (.dmp)

Open weabey opened this issue 5 years ago • 2 comments

hello,

I used Windows LiveKd - Windows Sysinternals tool to extract the memory dump and tried volatility for analyse the same. However i could not figure out the imageinfo cannot proceed further. any-idea on how to solve this ?

Capture

weabey avatar Jan 29 '20 21:01 weabey

Hi,

I've the same issue, probably your dump come from a pro or eentreprise version of windows 10, memory seems to be crypted..

@+

__ Philippe

frenchy35 avatar Jan 30 '20 07:01 frenchy35

Can you please try with the latest version of Volatility by using a checkout from here (GitHub)? I see that you are running what appears to be the standalone executable, which is extremely old at this point.

atcuno avatar May 13 '20 22:05 atcuno