Live Forensics | How to Install Volatility 3 on Windows 11 Windows 10 | Symbol Tables Configuration

แชร์
ฝัง
  • เผยแพร่เมื่อ 10 พ.ย. 2024

ความคิดเห็น • 31

  • @CyDig
    @CyDig  8 หลายเดือนก่อน +2

    Please consider sharing my videos.
    Recover word document docx from Network Traffic using Wireshark | An investigation into Ann Bad AIM th-cam.com/video/T193mUn5a2I/w-d-xo.htmlsi=P6O1kOjSthS5Idp7
    Searching All Areas of the Digital Forensic Image for Deleted Text Using Linux Commands Grep | XXD th-cam.com/video/dDgnU_o2lYA/w-d-xo.htmlsi=-CTJbCKrLKrZxbmU
    Digital Forensic Report Template | Expert Witness Report Template th-cam.com/video/9P4UlI4cLJ4/w-d-xo.htmlsi=T4XDigEELPy2yfIT
    Digital Forensic Investigation Case in OpenText EnCase 23 | Part 1 How to add evidence files
    th-cam.com/video/YyHYygkbPQ8/w-d-xo.htmlsi=q59JBrjEGLwgshg6
    Discover Cybersecurity Degree in the UK 2024 | Uncover the Secrets to Choosing the Right University
    th-cam.com/video/SCSpCXrAXn8/w-d-xo.htmlsi=41d88KT96uq33baZ
    How to Write Project Proposal using ChatGPT for UG, MSc, and PhD | Full Tutorial
    th-cam.com/video/kw2hX0Xla1w/w-d-xo.htmlsi=73opdAdCAIYK-usN
    Penetration Testing & Ethical Hacking | XMAS scan Vs SYN scan | Understand them U Nmap and WireShark
    th-cam.com/video/LIcyExXpLhY/w-d-xo.htmlsi=KmCz4S0LR7bbyCMY
    How to get network connection information ( telnet ) from RAM memory? Using volatility 3. Password ?
    th-cam.com/video/Nh9H3qQ8wBY/w-d-xo.htmlsi=KEl-f18o3WlgQpsL
    How to make a Forensic Image with FTK Imager | Forensic Acquisition in Windows | Physical Disk Image
    th-cam.com/video/8fJWQilA9U8/w-d-xo.htmlsi=SMN-RP7m4rjdPVM9
    Live Forensic RAM analysis Windows 10 - FTK Imager - Extract and recover jpeg picture file from RAM. th-cam.com/video/v7HdicjMtPU/w-d-xo.htmlsi=CgY4QNAij1FPtuAI

  • @NoWay01-yd8xc
    @NoWay01-yd8xc ปีที่แล้ว +1

    Thanks for making this. Volatility 3!

  • @DreamLifeAfrica
    @DreamLifeAfrica ปีที่แล้ว +1

    Volatility 3 has different commands that volatility 2. Good video ❤

  • @ricardosilva-wq5rj
    @ricardosilva-wq5rj 10 หลายเดือนก่อน

    What a man! what a legend! thank you so much!

    • @CyDig
      @CyDig  10 หลายเดือนก่อน

      Glad it helped!

  • @AlexAli-e2o
    @AlexAli-e2o ปีที่แล้ว +1

    Good stuff as usual!

  • @rushmid4639
    @rushmid4639 4 หลายเดือนก่อน +1

    Amazing instructor ♥

    • @CyDig
      @CyDig  3 หลายเดือนก่อน

      Thank you!

  • @henryldr
    @henryldr ปีที่แล้ว +1

    thank you so much bro!

  • @GraphicsByStorm
    @GraphicsByStorm ปีที่แล้ว +1

    I keep getting the error FileNotFoundError: Could not find module 'C:\Program Files\Python310\DLLs\libyara.dll' (or one of its dependencies). Try using the full path with constructor syntax. when trying to run volatility.

    • @CyDig
      @CyDig  ปีที่แล้ว

      Are you using Windows PowerShell X86 or 64?
      Also, you may try reinstalling Python 3, and I am sure it will work.

  • @m200is
    @m200is ปีที่แล้ว +1

    I did the video as it is, but the error "Unable to validate the plugin requirements" occurs.

    • @CyDig
      @CyDig  ปีที่แล้ว +1

      can you send mecan you share with us the command you have used? and the full error?

  • @danielcarcamomartinezdanie5855
    @danielcarcamomartinezdanie5855 ปีที่แล้ว +1

    Volatility 3 v2.4.1 is compatible with Windows Symbol Tables . no errors when using this version.

  • @b.u7191
    @b.u7191 วันที่ผ่านมา +1

    when i create memedump in acces ftk he shutdown my pc ?

    • @CyDig
      @CyDig  9 ชั่วโมงที่ผ่านมา

      Is your PC a Virtual machine? However you can try to use Magnet RAM Capture, it's free to download from www.magnetforensics.com/resources/magnet-ram-capture/

  • @AweleNwajei
    @AweleNwajei 10 หลายเดือนก่อน +1

    I legit hoped it would work, instead all i got is this
    C:\volatility\volatility3-1.0.0>python.exe .\vol.py -f C:\volatility\memdump.mem windows.info
    Volatility 3 Framework 1.0.0
    Progress: 100.00 PDB scanning finished
    Unsatisfied requirement plugins.Info.nt_symbols: Windows kernel symbols
    A symbol table requirement was not fulfilled. Please verify that:
    You have the correct symbol file for the requirement
    The symbol file is under the correct directory or zip file
    The symbol file is named appropriately or contains the correct banner
    Unable to validate the plugin requirements: ['plugins.Info.nt_symbols']

    • @CyDig
      @CyDig  10 หลายเดือนก่อน

      Make sure to download the Symbol Tables and save it within Volatility 3. And it should run.

  • @sruthisivaraman2290
    @sruthisivaraman2290 ปีที่แล้ว +1

    hi there. Where can I find a sample mem file? I would also like to know what to do if the translation requirement and symbol table requirement are not fulfilled while listing installed plugins?

    • @CyDig
      @CyDig  ปีที่แล้ว

      For sample files, you can easily create your own memory dump by watching this video using FTK Imager. th-cam.com/video/sLzNxtIbfrA/w-d-xo.html

    • @CyDig
      @CyDig  ปีที่แล้ว

      But if you need another memory dump challenges and files you can go to --> aboutdfir.com/education/challenges-ctfs/ and search for Memory

    • @CyDig
      @CyDig  ปีที่แล้ว

      And this could help github.com/stuxnet999/MemLabs

  • @davidvillarreal4603
    @davidvillarreal4603 ปีที่แล้ว +1

    For me, the comand for "netscan" doesn't work

    • @davidvillarreal4603
      @davidvillarreal4603 ปีที่แล้ว +1

      I checked again and now it work, was something with python

    • @CyDig
      @CyDig  ปีที่แล้ว

      @davidvillarreal4603 I'm glad to hear that.👍

  • @Ali-k6k1q
    @Ali-k6k1q 2 หลายเดือนก่อน +1

    Very helpfull

  • @yowiee5835
    @yowiee5835 ปีที่แล้ว +1

    Hi, I'm trying to do a project using this Volatility. I'm planning to give this volatility some interface for other people to use it. Do you think it is possible to work on it?

    • @CyDig
      @CyDig  ปีที่แล้ว +1

      Yes, it is possible to create your own graphical user interface. However, there is Volatility Workbench available to download at www.osforensics.com/tools/volatility-workbench.html that will do the same as you plan. But I recommend you do it as a project and share it with our community.

  • @fabian-jz6cx
    @fabian-jz6cx ปีที่แล้ว +1

    how to extract a process?

    • @CyDig
      @CyDig  ปีที่แล้ว +1

      You can extract any process into a file using process ID with the dump option. You can watch this video to learn how.
      th-cam.com/video/Nh9H3qQ8wBY/w-d-xo.html

  • @CyDig
    @CyDig  ปีที่แล้ว +2

    If you are interested in doing your university project, essay or thesis using Volatility, watch this video th-cam.com/video/kw2hX0Xla1w/w-d-xo.html
    Please make sure to subscribe to support our channel and for you to stay tuned.