Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

outdated upstream dependencies #1

Open
drzraf opened this issue May 11, 2024 · 1 comment
Open

outdated upstream dependencies #1

drzraf opened this issue May 11, 2024 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@drzraf
Copy link

drzraf commented May 11, 2024

  • volatility is restricted to Python2. volatility3 replaces it but the whole plugin API changed.
  • LiME project is archived. (tried on a recent kernel: it just hangs indefinitely). NB: I don't see why a system memory dump is necessary in the first place

Since the project is still very relevant nowadays, could one of this be realistic:

  • Updating to volatility3
  • Not relying on the volatility framework at all (only iasl)
    ?
@mdenzel mdenzel self-assigned this May 11, 2024
@mdenzel
Copy link
Owner

mdenzel commented May 11, 2024

Hello! :)

I already realized that volatility2 is deprecated. The API changes kept me from migrating this plugin as I have to rewrite the code entirely.

As for your remarks:

  1. LiME is only an example. You can use winpmem or linpmem or any other RAM dumping tool compatible with volatility.
  2. I am considering updating to volatility3 - currently busy detecting RAM injections on large scale, so migration will happen rather end of 2024 or 2025.
  3. Do you have a suggestion of how to get the ACPI tables without volatility/RAM dumps? (dumping from mainboard is not an option because the mainboard interface is controlled by the attacker when they flash the mainboard, so the attacker could return a clean image)

@mdenzel mdenzel added the enhancement New feature or request label May 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants