Comments (5)
Looks like there is an issue with the python unzip library and not an issue with CDQR coding itself. Recommend users unzip manually files that affected by the issue with python while how to get around it is researched
from cdqr.
@davidrudduck does the zip file get unzipped correctly by unzip
or other tools?
from cdqr.
@orlikoski yes, unzip
worked fine.
my CyLR collection list is a lot longer than the defaults so it's possible that one of the files I collect is unicode encoded and causing grief to the python based unzip library.
from cdqr.
Definitely good to know and this issue getting documented will help others who have run into the same problem as well as a solution to it. If it becomes a major issue we can research other options than the python zip library
from cdqr.
Just encountered the same issue with the docker version. Didn't understand how to solve it ?
user:/$ ./cdqr in:laptop out:Results_laptop -p win -z --max_cpu
Assigning CDQR to the host network
The Docker network can be changed by modifying the "DOCKER_NETWORK" environment variable
Example (default Skadi mode): export DOCKER_NETWORK=host
Example (use other Docker network): export DOCKER_NETWORK=skadi-backend
docker run --network host -v /home/user/tools/laptop/:/home/user/tools/laptop/ -v /home/user/tools/Results_laptop:/home/user/tools/Results_laptop aorlikoski/cdqr:5.0.0 -y /home/user/tools/laptop/ /home/user/tools/Results_laptop -z --max_cpu
CDQR Version: 5.0
Plaso Version: 20190331
Using parser: win
Number of cpu cores to use: 4
Destination Folder: /home/user/tools/Results_laptop
Attempting to extract source file: /home/user/tools/laptop
Unable to extract file: /home/user/tools/laptop
[Errno 21] Is a directory: '/home/user/tools/laptop'
from cdqr.
Related Issues (20)
- Add Splunk support HOT 2
- Database Filename Issues on Windows HOT 6
- Process not completing HOT 3
- Add support to accept defaults HOT 2
- CDQR Parsing when Timesketch Elastic Search Not running HOT 4
- Manage Timeout HOT 1
- add skip compressed file parameter HOT 6
- Error when Results folder already exists HOT 2
- What's the right way to run dead box collection? HOT 4
- Bypass pause at the end of CDQR processing HOT 1
- Add the ability to use plaso filters HOT 1
- Make MFT and USNJRNL Optional HOT 1
- Error when Unknown parser or plugin names HOT 3
- Can't parse zip if hostname contains '-' HOT 13
- Unknown parser or plugin names in element(s): "bash" HOT 3
- ZIP Not Found HOT 1
- CDQR does not parse Windows Event correctly to Kibana HOT 2
- Execution of cdqr.exe requires log2timeline.exe HOT 9
- log2timeline.py: error: unrecognized arguments: Results/artifacts/host1 HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from cdqr.