vol2以及mimikatz插件安装教程
volatility2安装
https://github.com/volatilityfoundation/volatility
git clone https://github.com/volatilityfoundation/volatility.git
进入对应目录安装
python2 setup.py install
mimikatz插件安装
mimikatz插件地址
https://github.com/volatilityfoundation/community/blob/master/FrancescoPicasso/mimikatz.py
此插件需要这个construct库的支持
复制到你对应的volatility/volatility/plugins/下
例如我这里是
root/桌面/volatility/volatility/plugins/
使用时在 -f 前指定对应的路径即可 --plugins=
vol.py --plugins=/root/桌面/volatility/volatility/plugins/ -f /root/桌面/WIN-DOOJTVIN21M-20231005-091206.raw --profile=Win7SP1x64 mimikatz
常见问题
如果出现
*** Failed to import volatility.plugins.mimikatz (AttributeError: 'module' object has no attribute 'ULInt32')
就是construct版本的问题
sudo pip uninstall construct
sudo pip install construct==2.5.5-reupload
这时就可以正常使用了

浙公网安备 33010602011771号