From e5d51eb9b7786d97f953e3f81124fad137cc3b89 Mon Sep 17 00:00:00 2001 From: Jan Date: Fri, 17 Jul 2020 19:01:09 +0200 Subject: [PATCH] adds dynamic length of pool header alignments --- volatility/framework/plugins/windows/poolscanner.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/volatility/framework/plugins/windows/poolscanner.py b/volatility/framework/plugins/windows/poolscanner.py index 708e45694..4c4f9744d 100644 --- a/volatility/framework/plugins/windows/poolscanner.py +++ b/volatility/framework/plugins/windows/poolscanner.py @@ -361,7 +361,12 @@ class PoolScanner(plugins.PluginInterface): if not is_windows_10: scan_layer = context.layers[scan_layer].config['memory_layer'] - for constraint, header in cls.pool_scan(context, scan_layer, symbol_table, constraints, alignment = 8): + if symbols.symbol_table_is_64bit(context, symbol_table): + alignment = 0x10 + else: + alignment = 8 + + for constraint, header in cls.pool_scan(context, scan_layer, symbol_table, constraints, alignment = alignment): mem_object = header.get_object(type_name = constraint.type_name, use_top_down = is_windows_8_or_later,