-
Notifications
You must be signed in to change notification settings - Fork 44
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update VelociraptorLoader based on version 0.7.0 #358
Conversation
The volumes and paths are mapped correctly but the NTFS is not correctly parsed. I will try to find the bug that causes this.
|
Codecov Report
@@ Coverage Diff @@
## main #358 +/- ##
==========================================
+ Coverage 71.76% 71.77% +0.01%
==========================================
Files 238 238
Lines 18689 18702 +13
==========================================
+ Hits 13412 13424 +12
- Misses 5277 5278 +1
Flags with carried forward coverage won't be shown. Click here to find out more.
📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more |
Looks like it tries to open the |
It does collect the file but with a file size of I expect that the bug will be fixed in the next release of Velociraptor. I have changed the PR to ready for review because the loader functions correctly. |
A cleaner fix might be to check for When checking for stat/opening afterwards, it might be best to "optimize" that by doing a |
…ct.target into fix/velociraptor_loader
Okay I have added a check and now the functions work on the targets. target-query -t * -f hostname,os -q
<Target VSSAnalysisAge-N> windows MSEDGEWIN10
<Target VSSAnalysisAge-Y> windows MSEDGEWIN10
<Target autoaccessor-N> windows MSEDGEWIN10
<Target autoaccessor-Y> windows MSEDGEWIN10 Nice that the NTFS parser uses default values in case there is no |
e18375b
to
65b5190
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Small nitpicky comment, good to go otherwise.
…ct.target into fix/velociraptor_loader
Add new Velociraptor NTFS accessors