First draft of a ContextBuilding system.

This commit is contained in:
Mike Auty
2015-01-09 01:55:32 +00:00
parent cd07ff17b2
commit 246974de36
2 changed files with 100 additions and 0 deletions
+71
View File
@@ -0,0 +1,71 @@
import volatility
from volatility.framework.interfaces import layers
from volatility.framework.symbols import vtypes, native, windows
__author__ = 'mike'
from volatility.framework import interfaces
class ContextPhysicalLoader(interfaces.context.ContextFactory):
def construct_physical_layers(self, context):
# TODO: Add in the physical layer automagic to determine the layering
# Ideally allow for the plugin to specify the layering, but if not then guess at the best one
base = layers.physical.FileLayer(context, 'data', filename = '/home/mike/memory/private/jon-fres.dmp')
context.add_layer(base)
### NATIVE TYPES
class Context32Bit(ContextPhysicalLoader):
def construct_context(self):
"""Creates a base context with the 32-bit NativeTables"""
native_list = native.x86NativeTable
return volatility.framework.Context(native_list)
class Context64Bit(ContextPhysicalLoader):
def construct_context(self):
"""Creates a base context with the 32-bit NativeTables"""
native_list = native.x64NativeTable
return volatility.framework.Context(native_list)
### INTEL SPACES
class ContextIntel(Context32Bit):
def construct_architecture(self, context):
# TODO: Determine the DTB
intel = layers.intel.Intel(context, 'kernel', 'data', page_map_offset = 0x319000)
context.add_layer(intel)
class ContextIntelPAE(Context32Bit):
def construct_architecture(self, context):
# TODO: Determine the DTB
intel = layers.intel.IntelPAE(context, 'kernel', 'data', page_map_offset = 0x319000)
context.add_layer(intel)
class ContextIntelX64(Context64Bit):
def construct_architecture(self, context):
# TODO; Determine the DTB
intel = layers.intel.Intel32e(context, 'kernel', 'data', page_map_offset = 0x319000)
context.add_layer(intel)
### Operating Systems
class ContextWindowsX86(ContextIntel):
# TODO: Only import the vtypes during init
def __init__(self):
from volatility.framework import xp_sp2_x86_vtypes
self.virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
def construct_os_symbols(self, context):
virtual_types = self._virtual_types
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types)
ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD)
ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY)
context.symbol_space.append(ntkrnlmp)
@@ -44,3 +44,32 @@ class ContextInterface(object, metaclass = ABCMeta):
Returns a fully constructed object
"""
class ContextFactory(object, metaclass = ABCMeta):
"""Class to establish and load the appropriate components of the context for a given operating system"""
def establish_context(self):
"""Constructs a standard context based on the architecture information
The context is modified
"""
context = self.construct_context()
self.construct_physical_layers(context)
self.construct_architecture(context)
self.construct_os_symbols(context)
@abstractmethod
def construct_context(self):
"""Returns a context based on some native types"""
@abstractmethod
def construct_physical_layers(self, context):
"""Adds a 'physical' layer to the context that should be used by the architecture, and any additional layers that might be usable by the architecture"""
@abstractmethod
def construct_architecture(self, context):
"""Applies the architecture mapping layer, using the primary 'physical' layer and any other layers it can additionally make use of"""
@abstractmethod
def construct_os_symbols(self, context):
"""Add the appropriate symbols for the operating system"""