ufrisk/MemProcFS

No netstat output in a working memory dump (Windows 7 and XP)

SolitudePy opened this issue · 3 comments

Hello, I tried running memprocfs on the known cridex.vmem. it can be found online, the memory is Windows XP I wonder if the tool support that since netstat output comes empty, while volatility sockets is able to show it.
Great tool by the way!

It does not support windows XP network connections currently.

Windows XP was ancient and no longer really used in the real world when this tool was created.

I never could warrant myself spending the time required to add it, especially since microsoft completely remade the network stack since. Network connections in Win8 memory and onwards should be mostly fine though.

I should clarify this in the guide pages or add a readme/info file in the file system to clarify though.

@ufrisk I understand, thanks

I believe this is a duplicate issue of #283

I should be looking into this I guess since it seems like Windows 7 is still quite popular in CTF's and memory forensics classes. I'm closing this issue though and keeping the other one open until it's been added.