From 09ee972e7e4b55086021adc79ecdfaf837b5e026 Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Fri, 2 Jan 2015 00:12:28 +0000 Subject: [PATCH] Add in initial version of _LIST_ENTRY. --- .../framework/symbols/windows/__init__.py | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/volatility/framework/symbols/windows/__init__.py b/volatility/framework/symbols/windows/__init__.py index 34de0d5ea..6e6ddf1da 100644 --- a/volatility/framework/symbols/windows/__init__.py +++ b/volatility/framework/symbols/windows/__init__.py @@ -7,3 +7,27 @@ class _ETHREAD(objects.Struct): def owning_process(self, kernel_layer = None): """Return the EPROCESS that owns this thread""" return self.ThreadsProcess.dereference(kernel_layer) + + +class _LIST_ENTRY(objects.Struct): + def to_list(self, structure, member, forward = True, sentinel = True, layer = None): + """Returns an iterator of the entries in the list""" + + if layer is None: + layer = self._layer_name + + relative_offset = self._context.symbolspace.relative_child_offset(structure, member) + + direction = 'BLink' + if forward: + direction = 'FLink' + link = getattr(self, direction).dereference() + + seen = set() + while link.offset not in seen: + + object = self._context.Object(structure, layer, offset = link.offset) + yield object + + seen.add(link.offset) + link = getattr(link, direction).dereference()