volatility3
volatility3 copied to clipboard
Thread detailed info on a separate plugin / timeline
I've noticed a volatility plugin can find detailed thread information in memory dumps such as: Priority, flags, start address, creation time, etc
However, currently Vol3 doesn't support this plugin or any detailed thread info.
Need this for many useful correlations with other events in the timeline
So thanks for filing this issue, I think this might actually be a duplicate of #118 since that also requests the threads plugin. I'll leave this open for a bit so it's more visible, but discussion about it will probably go on in that bug instead...