Hi Mark,
Did you install the registry plugins (that contain hivescan)? Make
sure you get all supporting libraries installed. You can check
Moyix's blogpost
(
http://moyix.blogspot.com/2009/01/memory-registry-tools.html) on how
to install/use it and there are also installation manuals on the
Documentation wiki that cover it as well
(
http://code.google.com/p/volatility/wiki/DocFiles) Also, you may
want to use the framework from the SVN
(
http://code.google.com/p/volatility/source/checkout) if you haven't
already (there's also documentation on how to use SVN on the
documenation wiki)...
As Darren also said, the forensics wiki
(
http://www.forensicswiki.org/wiki/List_of_Volatility_Plugins) has a
pretty good list of current Volatility plugins.
All the best,
-gleeda
Date: Mon, 28 Jun 2010 22:09:02 +0000 (UTC)
From: mark-wade(a)comcast.net
Subject: [Vol-users] Third Party plugins
To: vol-users(a)volatilityfoundation.org
Message-ID:
<1973170622.78668.1277762942105.JavaMail.root(a)sz0109a.westchester.pa.mail.comcast.net>
Content-Type: text/plain; charset="utf-8"
Hello,
I am trying to see if there is a list or repository anywhere for third party plugins .
Also, I am running the hivescan with the1.3 Beta. I dumped the hivescan plugin package in
the Volatility directory, but when I run it I am getting the message: Error: Invalid
module [ hivescan ]. Are there any docs to address running third party apps with
Volatility ? I am running it on Windows.
Thanks