Comments (6)
After using pythonpath switch, not getting the previous error, however, PY initialization was failed.
from memprocfs.
Thanks for reporting. I tried this on a clean install system (win10) with recent MemProcFS and Python and I haven't been able to replicate the issue.
- what operating system are you running on? Windows 10 and which release or Windows 7?
- what exact python version are you running? What does it say when you start Python both in 1st post and 2nd post. Note that if you happen to be running a 32-bit python that may be the issue (only 64-bit is supported) I should really update the error message. But 32/64-bit does not explain your error message in 1st post.
from memprocfs.
Hello Master,
Thanks for checking 👍
-
The Windows version is 10 and as you see in the first post it is 18363 build.
-
MemProcFS is the latest downloaded from GitHub repo (MemProcFS_files_and_binaries_v3.3-20200804-2).
Without using Python Path, I am getting following exception.
After using PY path: PluginManager PY initialization failed.
However, I can see the mounted file system. But thinking about Python, as PY API can not be used due to this failure.
The other help I need is to mount Linux memory. As usual, I need to pass the profile for a Linux memory, but unsure how I can specify that or how to retrieve the DTB/cr3 value for the Linux memory image.
from memprocfs.
Fortunately I got it for the Python Error. :) A silly mistake...
- Installed Python for all user under C:\Program Files
- Installed missing Plugin manager : pip install pluginmanager
Please need help for the Linux memory image as requested in previous post. :) Though I read that MemProcFS is supporting Windows only. But was wondering if DMA is possible through FPGA and Linux memory is accessible through PCILeech, we may read the Linux memory in the exact same way as we do for Windows using MemProcFS.
from memprocfs.
Thank you for the update; it's good to see that it's working.
About analyzing linux images; it's not really supported bar for the very most basic functionality - i.e. analyzing one single process at a given time by supplying its -cr3 / dtb value. I'm not aware about how to find this value in a good way in Linux. For testing I used a kernel module inserted in my test system.
Long story short; MemProcFS is next to useless when it comes to analyzing Linux. You'd be much better off using another tool such as Volatility for Linux.
A tool like this is a lot of work. I've been doing this on my free spare time as a hobby project for some time now. I figured I had better to focus on the OS with the larger market share and make a nice usable really awesome product for that rather than create something mediocre that works just a little on many platforms. I'm not likely to add Linux support any time soon due to lack of time.
Please let me know if you come to think about missing Windows-related analysis features and tasks though. I plan to add some kind of malware scan functionality quite soon. Also if you do find it useful I've opened up for sponsorships via Github sponsors very recently. Just $2 contributed will become $4 for me (Github matches every sponsor contribution).
from memprocfs.
I'm closing this issue since the problem seems to be resolved.
from memprocfs.
Related Issues (20)
- MemProcFS C# API: problem with reading file HOT 4
- Minor Typo HOT 2
- Please add -V or -version option HOT 4
- Add check option? HOT 3
- VMMDLL_Map_GetHeapAlloc() VMMDLL_MAP_HEAPALLOCENTRY.cb off by 8 low HOT 3
- Python process.maps.heapalloc() size and memory read issues. HOT 1
- Rust API: VmmYaraResult.result is empty even if VmmYaraResult.total_results>0. HOT 9
- How do you set the interval in the configset vmmdll_opt_refresh HOT 2
- Question: Best way to get findevil results from Rust API HOT 3
- VMMDLL_Initialize init problems on AMD + LINUX HOT 1
- Some Windows 7 memory images cannot analyze dst ip and dst port. HOT 1
- An issue with mounting image files HOT 2
- How can I achieve threading with this? (rust) HOT 1
- Can we further optimize it HOT 3
- need kernl call Example HOT 1
- Java Vabase return minus value HOT 4
- C++ Scatter abnormal HOT 2
- rust: yara SIGSEGV HOT 12
- Rust API: Yara Match Rules are truncated HOT 7
- C++ freezing the Read Requests HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from memprocfs.