Hi Markus,
I'm running 2.3.1 from the SVN and have just tried the mftparser on two memory
captures from Win7SP1x64 - no problems for me: plenty of MFT records returned.
Do all the records returned look like that or just some?
Have you tried the same plugin against captures from a different 64-bit machine?
Adam
On Saturday, 12 April 2014, 1:57, markus neis <markus.neis(a)googlemail.com> wrote:
Hi,
is anybody else also running into issues when using mftparser on Win7 64 Bit?
I get the following:
WARNING : volatility.obj : Cant find object NullString in profile
<volatility.plugins.overlays.windows.win7.Win7SP1x64 object at 0xb4fc44c>?
Which results in entries like:
(FN)
0x184000|None\None\None\None\None\None\None|153380|---a-----------|0|0|480|1336379877|1336379877|1336379877|1336379877
Thanks,
Markus
_______________________________________________
Vol-users mailing list
Vol-users(a)volatilesystems.com
http://lists.volatilityfoundation.org/mailman/listinfo/vol-users