New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bug in the artifact filter (using groups) #2291
Comments
I'll take a look at this one. |
I'm taking a look at this as well. |
self._artifacts is modifying while iterating over it here: plaso/plaso/engine/artifact_filters.py Line 126 in e7fcf76
and here: plaso/plaso/engine/artifact_filters.py Line 128 in e7fcf76
Which is one part of the problem. Also, lists are converted to sets in artifact_filters.py, so the processing order is non-deterministic. |
Unfortunately, BrowserHistory on Windows relies on Plaso being able to expand the %%users.appdata%% variable, which it currently can't do. This in turn relies on dfwinreg supporting the HKEY_USERS key: which is also a work in progress. #2310 will clean up the error message, and address some other issues in artifact group support, but not completely resolve this issue. |
@Onager I assume this issue has been addressed, reopen if not the case |
Still not addressed, log2timeline/dfwinreg#73 is blocking full resolution of this. |
@Onager can you be a bit more detailed about what still needs to be addressed for the artifact groups? For other related artifacts support issues I've created:
|
This looks to be resolved now that the other artifacts changes are merged. |
Description of problem:
Tried to extract only browser history from an image using the artifact group filters.... instead of ending up with a plaso file filled with browser history I got an error and the tool died before producing any output.
Command line and arguments:
(using the XP tdungan image from SANS as an example)
Source data:
The XP tdungan image provided by SANS for the 508 class.
Plaso version:
Latest released version (not head)... 20181219
Operating system Plaso is running on:
Linux, good ol' fashion Debian GNU/Linux
Installation method:
Using apt-get from GIFT PPA
The text was updated successfully, but these errors were encountered: