1.安装distorm3
git clone https://github.com/vext01/distorm3 && cd distorm3 && python2 setup.py install
2.安装需要的库
pip2 install yara openpyxl ujson construct
3,软连接
ln -s /usr/local/lib/python2.7/dist-packages/usr/lib/libyara.so /usr/lib/libyara.so
4.安装Vol2
git clone https://github.com/volatilityfoundation/volatility.git && cd volatility && python2 setup.py install
5.查看volatility的安装目录
find /usr -name 'volatility'
6.进入插件目录
cd plugins
7.使用wget去github下载并命名为mimikatz.py
curl https://raw.githubusercontent.com/ruokeqx/tool-for-CTF/master/volatility_plugins/mimikatz.py >> mimikatz.py