-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Win7 build 23864 memdump doesn't work with any win7 profiles #451
Comments
That's pretty typical of DumpIt. I would recommend using Surge instead. Its not free, but it works: https://www.volexity.com/products-overview/surge/. |
@iMHLv2 are there any open source tools you would recommend? Have you seen the same behavior using the old moonsols win[32|64]dd.exe` ? |
No sir, none that I'm willing to vouch for. Back porting your acquisition software is a bad idea in general, because lots of things have been changing recently with regards to memory. So if the latest version of a tool doesn't work, its highly unlikely an older version would. If its a "clutch" situation (i.e. the target machine is about to get formatted) and you don't have time to procure a license, you may be able to get a trial copy. |
@iMHLv2 I am going to give FTK Imager a shot and if that doesn't work i'll get my boss's boss to fork over some cash for a commercial tool. Thanks! |
No worries, good luck. |
Hi all,
I am trying to do some forensics of an image i took with DumpIt on a windows7 x64 SP1 machine build 23864, and i'm not getting any output from
psxview
,pslist
,apihooks
etc...Here is some output of what I have tried so far:
imaginfo
kdbgscan
psscan --profile=Win7SP1x64
psscan --profile=Win7SP1x64_23418
psxview --profile=Win7SP1x64
pslist --profile=Win7SP1x64_23418
The text was updated successfully, but these errors were encountered: