From 70a9171fd4ffdf55cd96b9721484b9443a81665a Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Thu, 20 Feb 2025 09:24:38 +0000 Subject: [PATCH] Windows: Remove pid filtering option from threads --- volatility3/framework/plugins/windows/threads.py | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/volatility3/framework/plugins/windows/threads.py b/volatility3/framework/plugins/windows/threads.py index 84daa8595..f620eebef 100644 --- a/volatility3/framework/plugins/windows/threads.py +++ b/volatility3/framework/plugins/windows/threads.py @@ -31,12 +31,6 @@ class Threads(thrdscan.ThrdScan): description="Windows kernel", architectures=["Intel32", "Intel64"], ), - requirements.ListRequirement( - name="pid", - description="Filter on specific process IDs", - element_type=int, - optional=True, - ), requirements.PluginRequirement( name="thrdscan", plugin=thrdscan.ThrdScan, version=(1, 1, 0) ), @@ -74,12 +68,10 @@ class Threads(thrdscan.ThrdScan): layer_name = module.layer_name symbol_table_name = module.symbol_table_name - filter_func = pslist.PsList.create_pid_filter(context.config.get("pid", None)) - for proc in pslist.PsList.list_processes( context=context, layer_name=layer_name, symbol_table=symbol_table_name, - filter_func=filter_func, + filter_func=None, ): yield from cls.list_threads(module, proc)