Hello all,
I have tried the libforensic1394 package from
https://freddie.witherden.org/tools/libforensic1394/
with Volatility. That's the result:
# python vol.py -l Firewire://forensic1394/0 pslist
Volatile Systems Volatility Framework 2.1_alpha
No suitable address space mapping found
Tried to open image as:
WindowsHiberFileSpace32: No base Address Space
EWFAddressSpace: Location is not of file scheme
WindowsCrashDumpSpace32: No base Address Space
JKIA32PagedMemory: No base Address Space
IA32PagedMemoryPae: Module disabled
JKIA32PagedMemoryPae: No base Address Space
IA32PagedMemory: Module disabled
FileAddressSpace: Location is not of file scheme
What could I have missed? I had expected to to read something about the firewire address
space but neither Firewire:... nor firewire:... did work.
Regards
Michael
--
NEU: FreePhone - 0ct/min Handyspartarif mit Geld-zurück-Garantie!
Jetzt informieren:
http://www.gmx.net/de/go/freephone