Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dumpfile parse error #20

Closed
ggg4566 opened this issue Apr 27, 2022 · 5 comments
Closed

dumpfile parse error #20

ggg4566 opened this issue Apr 27, 2022 · 5 comments

Comments

@ggg4566
Copy link

ggg4566 commented Apr 27, 2022

Nano dump file size is only 9M mimikatz and pypykatz cannot be parsed normally . Procdump dumpfile is 35M

@S4ntiagoP
Copy link
Collaborator

S4ntiagoP commented Apr 27, 2022

Hello @ggg4566 , is the procdump dump parsed correctly?
The difference in size is normal. Also, try updating pypykatz to the latest version and try again.

@ggg4566
Copy link
Author

ggg4566 commented Apr 28, 2022

Hello @ggg4566 , is the procdump dump parsed correctly? The difference in size is normal. Also, try updating pypykatz to the latest version and try again.

pypykatz is the latest version, procdump dump can parse normal. Dumpfile cannot be parsed normally on win7 and win10
image

@ggg4566
Copy link
Author

ggg4566 commented Apr 28, 2022

@S4ntiagoP Use old version nanodump dump file can't be parsed normally, and the dumpfile grabbed on my colleague's computer is also the same result

@S4ntiagoP
Copy link
Collaborator

S4ntiagoP commented Apr 28, 2022

It is failing because of the invalid signature, restore it by running this on linux:
bash scripts/restore_signature.sh mem.dump

@ggg4566
Copy link
Author

ggg4566 commented Apr 29, 2022

It is failing because of the invalid signature, restore it by running this on linux: bash scripts/restore_signature.sh mem.dump

thank you! nice:)

@ggg4566 ggg4566 closed this as completed Apr 29, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants