diff --git a/volatility3/framework/plugins/windows/getservicesids.py b/volatility3/framework/plugins/windows/getservicesids.py index 2b5ab11f4..f8a78dfcd 100644 --- a/volatility3/framework/plugins/windows/getservicesids.py +++ b/volatility3/framework/plugins/windows/getservicesids.py @@ -62,13 +62,14 @@ class GetServiceSIDs(interfaces.plugins.PluginInterface): def _generator(self): - # Go all over the hives + # Get the system hive for hive in hivelist.HiveList.list_hives(context = self.context, base_config_path = self.config_path, layer_name = self.config['primary'], symbol_table = self.config['nt_symbols'], + filter_string = 'machine\\system', hive_offsets = None): - # Get ConrolSet\Services. + # Get ControlSet\Services. try: services = hive.get_key(r"CurrentControlSet\Services") except (KeyError, exceptions.InvalidAddressException): diff --git a/volatility3/framework/plugins/windows/getsids.py b/volatility3/framework/plugins/windows/getsids.py index 30503b2bf..89b1f5f4f 100644 --- a/volatility3/framework/plugins/windows/getsids.py +++ b/volatility3/framework/plugins/windows/getsids.py @@ -81,6 +81,7 @@ class GetSIDs(interfaces.plugins.PluginInterface): base_config_path = self.config_path, layer_name = self.config['primary'], symbol_table = self.config['nt_symbols'], + filter_string = 'config\\software', hive_offsets = None): try: