physmem2profit icon indicating copy to clipboard operation
physmem2profit copied to clipboard

RuntimeError: Unable to find a valid profile for this image. Try using -v for more details.

Open ctr1hub opened this issue 5 years ago • 2 comments

image

ctr1hub avatar Jan 25 '21 09:01 ctr1hub

If you take a full physical memory dump from the system, is Rekall able to analyze it correctly? What about Volatility 3?

Rekall has been discontinued after Physmem2profit was released so I need to start using Volatility 3 anyway. I'm hoping that will fix this issue.

timhir avatar Feb 04 '21 07:02 timhir

Any update on using volatility3?

I am trying to find a minidump creation module for lsass but maybe my google fu is not up to snuff.

If you happen to have any resources or one liners on how to create a minidump even from an offloaded physical memory file that would be great.

PS this project is awesome

Frogsecurity avatar Feb 14 '24 03:02 Frogsecurity