Skip to content

Conversation

@eve-mem
Copy link
Contributor

@eve-mem eve-mem commented Oct 9, 2024

Hello 👋

This PR renames the 'raw' mode to 'expert' and provides more warnings around it's use. There have been many issues with people attempting to analyze 'raw' formatted files with forensics tools such as volatility and failing because the memory is no longer aligned.

The existing warnings already explain this but it seems to be overlooked. By making the warnings even more verbose and making the option called expert hopefully that will deter normal users - while still allowing experts that wish to use this format if they wish.

🦊

@jtsylve
Copy link
Member

jtsylve commented Oct 9, 2024

I am fine with making the warnings more verbose if that would be useful, but I am hesitant to agree to changing the value of the parameter. This would break all existing automation scripts and tooling.

@eve-mem
Copy link
Contributor Author

eve-mem commented Oct 9, 2024

That makes sense. I'll remove those changes.

@jtsylve jtsylve merged commit 1f99bc6 into 504ensicsLabs:master Oct 14, 2024
NobodySpecial256 added a commit to NobodySpecial256/LiME that referenced this pull request Dec 19, 2024
Provide more warnings around use of this format. Closes 504ensicsLabs#111 (504ensicsLabs#121)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants