volatility3
volatility3 copied to clipboard
pdbconv cant create proper profile for win7 kernel(8199e3319bc8404581e451b565d048b81)
After installing KB5039289 and KB5039339 into Win7 machine, pdbconv cant create proper profile for it.
Version: 64-bit Windows 7
PE GUID: 66483bb65de000
PDB GUID: 8199e3319bc8404581e451b565d048b81
I tried to debug but I couldn't go into much detail. From what I understand it cannot read TPI. The maximum address and offset are equal to each other and it gets blocked here. https://github.com/volatilityfoundation/volatility3/blob/351db0e5730f1d1017141d57ee937d3f3d1fbc94/volatility3/framework/symbols/windows/pdbconv.py#L277