mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 21:44:52 +02:00
Windows Suspended Threads: Updates pe_symbols req
This bumps the requirement version number for pe_symbols, and uses the latest method signature. Co-authored-by: Andrew Case <andrew@dfir.org>
This commit is contained in:
co-authored by
Andrew Case
parent
e3ce4bc847
commit
d69b231f16
@@ -33,7 +33,7 @@ class SuspendedThreads(interfaces.plugins.PluginInterface):
|
||||
name="pslist", component=pslist.PsList, version=(2, 0, 0)
|
||||
),
|
||||
requirements.VersionRequirement(
|
||||
name="pe_symbols", component=pe_symbols.PESymbols, version=(1, 0, 0)
|
||||
name="pe_symbols", component=pe_symbols.PESymbols, version=(2, 0, 0)
|
||||
),
|
||||
requirements.VersionRequirement(
|
||||
name="threads", component=threads.Threads, version=(1, 0, 0)
|
||||
@@ -96,7 +96,7 @@ class SuspendedThreads(interfaces.plugins.PluginInterface):
|
||||
# will not have suspended threads
|
||||
if not proc_modules:
|
||||
proc_modules = pe_symbols.PESymbols.get_process_modules(
|
||||
self.context, kernel.layer_name, kernel.symbol_table_name, None
|
||||
self.context, self.config["kernel"], None
|
||||
)
|
||||
|
||||
path_and_symbol = functools.partial(
|
||||
|
||||
Reference in New Issue
Block a user