mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-28 20:44:52 +02:00
First draft of a ContextBuilding system.
This commit is contained in:
@@ -0,0 +1,71 @@
|
||||
import volatility
|
||||
from volatility.framework.interfaces import layers
|
||||
from volatility.framework.symbols import vtypes, native, windows
|
||||
|
||||
__author__ = 'mike'
|
||||
|
||||
from volatility.framework import interfaces
|
||||
|
||||
|
||||
class ContextPhysicalLoader(interfaces.context.ContextFactory):
|
||||
def construct_physical_layers(self, context):
|
||||
# TODO: Add in the physical layer automagic to determine the layering
|
||||
# Ideally allow for the plugin to specify the layering, but if not then guess at the best one
|
||||
base = layers.physical.FileLayer(context, 'data', filename = '/home/mike/memory/private/jon-fres.dmp')
|
||||
context.add_layer(base)
|
||||
|
||||
|
||||
### NATIVE TYPES
|
||||
|
||||
class Context32Bit(ContextPhysicalLoader):
|
||||
def construct_context(self):
|
||||
"""Creates a base context with the 32-bit NativeTables"""
|
||||
native_list = native.x86NativeTable
|
||||
return volatility.framework.Context(native_list)
|
||||
|
||||
|
||||
class Context64Bit(ContextPhysicalLoader):
|
||||
def construct_context(self):
|
||||
"""Creates a base context with the 32-bit NativeTables"""
|
||||
native_list = native.x64NativeTable
|
||||
return volatility.framework.Context(native_list)
|
||||
|
||||
|
||||
### INTEL SPACES
|
||||
|
||||
class ContextIntel(Context32Bit):
|
||||
def construct_architecture(self, context):
|
||||
# TODO: Determine the DTB
|
||||
intel = layers.intel.Intel(context, 'kernel', 'data', page_map_offset = 0x319000)
|
||||
context.add_layer(intel)
|
||||
|
||||
|
||||
class ContextIntelPAE(Context32Bit):
|
||||
def construct_architecture(self, context):
|
||||
# TODO: Determine the DTB
|
||||
intel = layers.intel.IntelPAE(context, 'kernel', 'data', page_map_offset = 0x319000)
|
||||
context.add_layer(intel)
|
||||
|
||||
|
||||
class ContextIntelX64(Context64Bit):
|
||||
def construct_architecture(self, context):
|
||||
# TODO; Determine the DTB
|
||||
intel = layers.intel.Intel32e(context, 'kernel', 'data', page_map_offset = 0x319000)
|
||||
context.add_layer(intel)
|
||||
|
||||
|
||||
### Operating Systems
|
||||
|
||||
class ContextWindowsX86(ContextIntel):
|
||||
# TODO: Only import the vtypes during init
|
||||
def __init__(self):
|
||||
from volatility.framework import xp_sp2_x86_vtypes
|
||||
|
||||
self.virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
|
||||
|
||||
def construct_os_symbols(self, context):
|
||||
virtual_types = self._virtual_types
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types)
|
||||
ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD)
|
||||
ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY)
|
||||
context.symbol_space.append(ntkrnlmp)
|
||||
@@ -44,3 +44,32 @@ class ContextInterface(object, metaclass = ABCMeta):
|
||||
Returns a fully constructed object
|
||||
"""
|
||||
|
||||
|
||||
class ContextFactory(object, metaclass = ABCMeta):
|
||||
"""Class to establish and load the appropriate components of the context for a given operating system"""
|
||||
|
||||
def establish_context(self):
|
||||
"""Constructs a standard context based on the architecture information
|
||||
|
||||
The context is modified
|
||||
"""
|
||||
context = self.construct_context()
|
||||
self.construct_physical_layers(context)
|
||||
self.construct_architecture(context)
|
||||
self.construct_os_symbols(context)
|
||||
|
||||
@abstractmethod
|
||||
def construct_context(self):
|
||||
"""Returns a context based on some native types"""
|
||||
|
||||
@abstractmethod
|
||||
def construct_physical_layers(self, context):
|
||||
"""Adds a 'physical' layer to the context that should be used by the architecture, and any additional layers that might be usable by the architecture"""
|
||||
|
||||
@abstractmethod
|
||||
def construct_architecture(self, context):
|
||||
"""Applies the architecture mapping layer, using the primary 'physical' layer and any other layers it can additionally make use of"""
|
||||
|
||||
@abstractmethod
|
||||
def construct_os_symbols(self, context):
|
||||
"""Add the appropriate symbols for the operating system"""
|
||||
|
||||
Reference in New Issue
Block a user