You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When I run imageinfo command on windows 10, 64 bits, standalone version, I cannot get any result. Here is the screenshot:
I am wondering whether my command is wrong, or my captured image has a problem.
I tried to capture the ram image in both raw and mem format. The tools I used were belkasoft and FTK imager. Both cannot work. I captured the image in a win 10 virtual machine with 1G ram, and transferred the image back to my host machine for analysis.
Please help. Thank you!
The text was updated successfully, but these errors were encountered:
First - the compiled version of Volatility (assuming you are using the one we distributed) is extremely old. You should instead use the latest version of Volatility from the GitHub master branch.
Second - If you have a VM then its best to capture using the virtual machine facilities.
Third - Both FTK Imager and Belkasoft are known to produce invalid memory samples from Windows 10 systems.
Please re-open this if you still have issues using the latest code and a better acquisition method.
When I run imageinfo command on windows 10, 64 bits, standalone version, I cannot get any result. Here is the screenshot:
I am wondering whether my command is wrong, or my captured image has a problem.
I tried to capture the ram image in both raw and mem format. The tools I used were belkasoft and FTK imager. Both cannot work. I captured the image in a win 10 virtual machine with 1G ram, and transferred the image back to my host machine for analysis.
Please help. Thank you!
The text was updated successfully, but these errors were encountered: