The "imagecopy" plugin in Volatility 2.4 does not decompress hiberfil.sys
files from Windows 8 machines, at least in the tests that I have tried. In
most cases, I'm getting identical files out, which means that the
hiberfil.sys wasn't translated into a native physical address space, which
suggests it's not supported? I have also tried using the Moonsols Windows
Memory Toolkit which claims to support Windows 8, but that software seems
to fail as well.
Has anybody had any luck with uncompressing a Windows 8 hiberfil.sys file?
Is there any other tool I can use to accomplish this?
TIA