Skip to content
This repository was archived by the owner on May 16, 2025. It is now read-only.

Wndows 10 Memory Compression#642

Open
MalwareMechanic wants to merge 3 commits intovolatilityfoundation:masterfrom
mandiant:win10_compressed_memory
Open

Wndows 10 Memory Compression#642
MalwareMechanic wants to merge 3 commits intovolatilityfoundation:masterfrom
mandiant:win10_compressed_memory

Conversation

@MalwareMechanic
Copy link

@btaubmann
Copy link

hey, is there a reason why this not merge to master, yet?
In my experiments it did not work with Win10x64_17134.
With my Win10x64_18362 image it looks as if it would work

@dmikushin
Copy link

Thanks for working on this PR! For hiberfil.sys, I still get:

DEBUG   : volatility.debug    : Succeeded instantiating <volatility.plugins.addrspaces.standard.FileAddressSpace object at 
...
DEBUG   : volatility.debug    : Failed instantiating (exception): Struct PO_MEMORY_IMAGE has no member FirstTablePage

This is Win10x64_18363, but I guess your patch only covers raw memory dumps, and not the hiberfil?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants