-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fatal Error on Win 10 Business N #13
Comments
Thanks for reporting... The logs indicate it seems to happen right after collecting the ServiceEventLogs artifact: https://github.com/CCXLabs/CCXDigger/blob/master/artifacts/CyberCX/Windows/ServiceEventLogs.yaml#L8 and the stack overflow means it is recursing too much into something (but we dont know what). Does it provide more of a backtrace? I wonder if it has something to do with the SearchVSS flag - do you have a lot of VSS copies on your system? |
Thanks for the quick reply,
This is a testing laptop with a small ssd disk that is generally close to being full most of the time. It has a 3Tb external hdd (usb) pretty much permanently attached (and was attached at the time of the test) and has a mapped drive to a samba fileserver. I've attached the full console output when the tool is run. |
I located the following in an event log on the device:
This was generated around the time I first ran the tool yesterday. A similar entry has not been created however when I ran the tool to get the console output this morning. I should have mentioned that this laptop is Azure AD joined as I have been testing various security options. |
Thanks for the error report - very detailed. I think I have a fix but I am finding it hard to replicate on a real system. |
I'd be happy to do any testing you need on this device if that would help? |
Thanks that would be great! You can rebuild the collector with the CCXLabs artifacts like this:
You can also just collect the same artifacts directly from the client (The |
Hi,
I ran the executable from admin command prompt and consistently get the following failure:
The run log is attached.
Collector_velociraptor.exe.log
The text was updated successfully, but these errors were encountered: