-
Notifications
You must be signed in to change notification settings - Fork 389
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feature: implement Timers
plugin.
#695
Feature: implement Timers
plugin.
#695
Conversation
I would wait untill #694 is merged so that the |
Hello @paulkermann, Thank you for your opinion. If possible, could you explain the difference between Also, in order to access the If I am mistaken or if there is any improvement, please leave an additional thread. |
The the the |
@paulkermann, Thank you for your detailed explanation. |
I tried to access the first block of |
@digitalisx I kinda tricked you. |
…lity3 into feature/timers
I've received a lot of feedback and help with the PR, but I think it's going to take some time for it to develop into a testable form (in fact, we need to check the data in the structure and convert it into code..) I can imagine in my head what structure to follow, but it doesn't seem to work when I try to code it and get it. (I probably need a little bit more understanding of libraries and functions.) 🧐 It's good to be able to exchange opinions and show what's going on through Draft PR, but if there's no progress, I'd like to close it for a while so that other members of the community can contribute. Perhaps the PR will be closed soon, I will open it again whenever I have the basis or clear preparation to discuss the proposal again. 😊 |
Fair enough, you're welcome to keep this PR open if you'd like advice on it as you go? I'm not sure where other people would help to contribute to this plugin other than on here, but if you'd like to close that will be ok too. |
@ikelos All right, I'll keep that PR. There are a lot of challenges before I solve this myself, but if we have any members who want to help or participate, please feel free to leave a thread. The new completed PR is good, too! 🙌 It may take a long time, but let's take a leisurely look. |
It's been a year since Draft PR, but I think I found a key code to fix this while watching closely. (#976) |
Description
Hello, everyone in the community! 😃
There are some plugins that have not been implemented as they are updated from Volatility 2 to 3.
After reviewing this #118, I found that Timers plugin has not yet migrated to 3.
So I will be implement (or porting) of Timers plugin according to the Volatility 3 structure.
It will be implement so that the same results as Volatility 2 can be obtained by referring to the existing code.
The difference is that this plugin does not support older operating systems (less than Windows 7).
Over time, I think don't need it's worth it to support the under versions.
Command
Help Command
Run Command
python3 vol.py -f case.vmem windows.timers
Expect Result
timers
plugin migration.timers
plugin results.Tasks
And this time, I decided to use Draft PR.
It's a good idea to request a full version of the Fork Repository and review it right away, but it seems to have the advantage of being able to open a full request from the start of work and anyone can talk to you anytime.
(This is one of the great philosophies described in Github.)
Unfortunately, the contribution guide for Volatility 3 has not been documented, but please let us know the organizers' opinions! I'll follow it. 🙂