volatilityfoundation / volatilityfoundation/volatility3

Missing notepad and clipboard plugins from volatility 2

Open
#710 4 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

low-priority plugin-request
Dominant language
Python
Stars
4.4k
Forks
705
Avg merge
1d 10h
Merged PRs (30d)
3

Description

Some of the functions of vol2 are not available to me in vol3.
e.g. vol -f xxx notepad or vol -f xxx clipboard
Even there is no way to view the history of the command line.
This is fatal to forensics.
I am currently unable to use vol3 to complete normal forensic actions, can you please make vol3 compatible with vol2 as soon as possible?
I do love the fast and modular design of vol3 and I hope vol3 will one day replace vol2 in the future.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by comparing the missing vol2 notepad, clipboard, and command-line-history functions with vol3; the issue does not identify files or tests. Completion would mean vol3 supports these requested forensic actions while retaining its modular design, with each command verified against a memory image.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cli, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.