We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents 2e57779 + aa04b8c commit e17cb15Copy full SHA for e17cb15
volatility3/framework/plugins/windows/vadinfo.py
@@ -198,6 +198,7 @@ def vad_dump(
198
199
def _generator(self, procs):
200
kernel = self.context.modules[self.config["kernel"]]
201
+ kernel_layer = self.context.layers[kernel.layer_name]
202
203
def passthrough(_: interfaces.objects.ObjectInterface) -> bool:
204
return False
@@ -229,7 +230,7 @@ def filter_function(x: interfaces.objects.ObjectInterface) -> bool:
229
230
(
231
proc.UniqueProcessId,
232
process_name,
- format_hints.Hex(vad.vol.offset),
233
+ format_hints.Hex(kernel_layer.canonicalize(vad.vol.offset)),
234
format_hints.Hex(vad.get_start()),
235
format_hints.Hex(vad.get_end()),
236
vad.get_tag(),
0 commit comments