-
Notifications
You must be signed in to change notification settings - Fork 143
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Third party plugins issue #1
Comments
hrmmm I'm not sure what the problem is, it should work if you've done what you said here. Out of curiosity, did you try just copying the
|
oh wait, i see what the problem is, sorry! You have to specify
|
Aha, thank you, I figured it might be user error, but I couldn't find Now, however, when I try to run autoruns (not mimikatz, which is *** Failed to import volatility.plugins.mimikatz (ImportError: No module On Mon, Mar 16, 2015 at 3:51 PM, gleeda notifications@github.com wrote:
|
Yes, you need to install the you can find info about it here: https://pypi.python.org/pypi/construct (Edited for note: the autoruns plugin is not the one failing, you are getting that failure because there's an issue with the mimikatz plugin since it can't import the missing library) |
Duh, I feel pretty dumb. Thank you so much for your help! Mimikatz is Volatility Foundation Volatility Framework 2.4 On Mon, Mar 16, 2015 at 4:27 PM, gleeda notifications@github.com wrote:
|
That's weird, I don't have that option and I just downloaded his plugin from github: https://github.com/tomchop/volatility-autoruns Maybe you should redownload it and try again if you didn't get it from there. If you can't get it working, ask the author for help (you can add an issue on his github or he's pretty easy to catch on twitter https://twitter.com/tomchop_ ). |
Alright, I'll play with it some more tomorrow =) Thanks again for all the On Mon, Mar 16, 2015 at 4:45 PM, gleeda notifications@github.com wrote:
|
No problem! I'm going to close this issue out for now. Feel free to reopen as needed. |
I recently heard about some very cool volatility plugins like autoruns and mimikatz, just to name a couple. On my Kali Linux machine I put these plugins into the /usr/share/volatility/contrib/plugins folder, and then have tried running the pulgins with vol.py -f file --profile=profile --plugins=contrib/plugins autoruns
But it just gives me the line "You must specify something to do." I've tried listing the full path for --plugins=/usr/share/volatility/contrib/plugins. I've tried listing the .py in the plugin name (autoruns.py,) and I keep getting the same issue. I've googled around to see if I could find something about some Kali specific directory or oddity in the volatility install, but I haven't found any useful information.
Any advice on what to try or what I'm doing wrong will be greatly appreciated!
-Thanks
The text was updated successfully, but these errors were encountered: