volatility3 icon indicating copy to clipboard operation
volatility3 copied to clipboard

Thread detailed info on a separate plugin / timeline

Open MrBR0B0T opened this issue 4 years ago • 1 comments

I've noticed a volatility plugin can find detailed thread information in memory dumps such as: Priority, flags, start address, creation time, etc

However, currently Vol3 doesn't support this plugin or any detailed thread info.

Need this for many useful correlations with other events in the timeline

MrBR0B0T avatar Jan 21 '21 21:01 MrBR0B0T

So thanks for filing this issue, I think this might actually be a duplicate of #118 since that also requests the threads plugin. I'll leave this open for a bit so it's more visible, but discussion about it will probably go on in that bug instead...

ikelos avatar Jan 22 '21 00:01 ikelos