diff --git a/volatility/framework/contexts/__init__.py b/volatility/framework/contexts/__init__.py new file mode 100644 index 000000000..b5f36534d --- /dev/null +++ b/volatility/framework/contexts/__init__.py @@ -0,0 +1,71 @@ +import volatility +from volatility.framework.interfaces import layers +from volatility.framework.symbols import vtypes, native, windows + +__author__ = 'mike' + +from volatility.framework import interfaces + + +class ContextPhysicalLoader(interfaces.context.ContextFactory): + def construct_physical_layers(self, context): + # TODO: Add in the physical layer automagic to determine the layering + # Ideally allow for the plugin to specify the layering, but if not then guess at the best one + base = layers.physical.FileLayer(context, 'data', filename = '/home/mike/memory/private/jon-fres.dmp') + context.add_layer(base) + + +### NATIVE TYPES + +class Context32Bit(ContextPhysicalLoader): + def construct_context(self): + """Creates a base context with the 32-bit NativeTables""" + native_list = native.x86NativeTable + return volatility.framework.Context(native_list) + + +class Context64Bit(ContextPhysicalLoader): + def construct_context(self): + """Creates a base context with the 32-bit NativeTables""" + native_list = native.x64NativeTable + return volatility.framework.Context(native_list) + + +### INTEL SPACES + +class ContextIntel(Context32Bit): + def construct_architecture(self, context): + # TODO: Determine the DTB + intel = layers.intel.Intel(context, 'kernel', 'data', page_map_offset = 0x319000) + context.add_layer(intel) + + +class ContextIntelPAE(Context32Bit): + def construct_architecture(self, context): + # TODO: Determine the DTB + intel = layers.intel.IntelPAE(context, 'kernel', 'data', page_map_offset = 0x319000) + context.add_layer(intel) + + +class ContextIntelX64(Context64Bit): + def construct_architecture(self, context): + # TODO; Determine the DTB + intel = layers.intel.Intel32e(context, 'kernel', 'data', page_map_offset = 0x319000) + context.add_layer(intel) + + +### Operating Systems + +class ContextWindowsX86(ContextIntel): + # TODO: Only import the vtypes during init + def __init__(self): + from volatility.framework import xp_sp2_x86_vtypes + + self.virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types + + def construct_os_symbols(self, context): + virtual_types = self._virtual_types + ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types) + ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD) + ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY) + context.symbol_space.append(ntkrnlmp) diff --git a/volatility/framework/interfaces/context.py b/volatility/framework/interfaces/context.py index 347f36976..677c35fa4 100644 --- a/volatility/framework/interfaces/context.py +++ b/volatility/framework/interfaces/context.py @@ -44,3 +44,32 @@ class ContextInterface(object, metaclass = ABCMeta): Returns a fully constructed object """ + +class ContextFactory(object, metaclass = ABCMeta): + """Class to establish and load the appropriate components of the context for a given operating system""" + + def establish_context(self): + """Constructs a standard context based on the architecture information + + The context is modified + """ + context = self.construct_context() + self.construct_physical_layers(context) + self.construct_architecture(context) + self.construct_os_symbols(context) + + @abstractmethod + def construct_context(self): + """Returns a context based on some native types""" + + @abstractmethod + def construct_physical_layers(self, context): + """Adds a 'physical' layer to the context that should be used by the architecture, and any additional layers that might be usable by the architecture""" + + @abstractmethod + def construct_architecture(self, context): + """Applies the architecture mapping layer, using the primary 'physical' layer and any other layers it can additionally make use of""" + + @abstractmethod + def construct_os_symbols(self, context): + """Add the appropriate symbols for the operating system"""