diff --git a/volatility/framework/plugins/windows/memdump.py b/volatility/framework/plugins/windows/memdump.py index 6187278ed..fa93063b5 100644 --- a/volatility/framework/plugins/windows/memdump.py +++ b/volatility/framework/plugins/windows/memdump.py @@ -1,13 +1,16 @@ # This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # - +import logging from typing import List + from volatility.framework import exceptions, renderers, interfaces from volatility.framework.configuration import requirements from volatility.framework.renderers import format_hints from volatility.plugins.windows import pslist +vollog = logging.getLogger(__name__) + class Memdump(interfaces.plugins.PluginInterface): """Dump the addressable memory for a process""" @@ -40,19 +43,22 @@ class Memdump(interfaces.plugins.PluginInterface): proc_layer_name = proc.add_process_layer() proc_layer = self.context.layers[proc_layer_name] except exceptions.InvalidAddressException as excp: - vollog.debug("Process {}: invalid address {} in layer {}".format(pid, excp.invalid_address, excp.layer_name)) + vollog.debug( + "Process {}: invalid address {} in layer {}".format(pid, excp.invalid_address, excp.layer_name)) continue - #Create file for writing + # Create file for writing filedata = interfaces.plugins.FileInterface("{}.dmp".format(filename)) for mapval in proc_layer.mapping(0x0, proc_layer.maximum_address, ignore_errors = True): - vadd, _, vpage, page_size, maplayer = mapval - data = proc_layer.read(vadd, page_size, pad = True) + offset, size, mapped_offset, _, maplayer = mapval + data = proc_layer.read(offset, size, pad = True) try: filedata.data.write(data) except exceptions.InvalidAddressException: - vollog.debug("Unable to write {}'s address {} [ {} ]to {}.dmp".format(process_name, vadd, proc.UniqueProcessId, proc.UniqueProcessId)) + vollog.debug("Unable to write {}'s address {} [ {} ]to {}.dmp".format(process_name, offset, + proc.UniqueProcessId, + proc.UniqueProcessId)) continue try: @@ -60,16 +66,14 @@ class Memdump(interfaces.plugins.PluginInterface): self.produce_file(filedata) except exceptions.InvalidAddressException: result_text = "Unable to write {} [ {} ]to {}.dmp".format(process_name, proc.UniqueProcessId, filename) - - yield(0, (result_text,)) - - + + yield (0, (result_text,)) def run(self): filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)]) - return renderers.TreeGrid([ ("Creating the following files:", str)], + return renderers.TreeGrid([("Creating the following files:", str)], self._generator( pslist.PsList.list_processes(context = self.context, layer_name = self.config['primary'], symbol_table = self.config['nt_symbols'], - filter_func = filter_func))) \ No newline at end of file + filter_func = filter_func))) diff --git a/volatility/framework/plugins/windows/memmap.py b/volatility/framework/plugins/windows/memmap.py index e3f03d08b..552f3fb6c 100644 --- a/volatility/framework/plugins/windows/memmap.py +++ b/volatility/framework/plugins/windows/memmap.py @@ -1,13 +1,16 @@ # This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # - +import logging from typing import List + from volatility.framework import exceptions, renderers, interfaces from volatility.framework.configuration import requirements from volatility.framework.renderers import format_hints from volatility.plugins.windows import pslist +vollog = logging.getLogger(__name__) + class Memmap(interfaces.plugins.PluginInterface): """Prints the memory map""" @@ -37,26 +40,27 @@ class Memmap(interfaces.plugins.PluginInterface): proc_layer = self.context.layers[proc_layer_name] except exceptions.InvalidAddressException as excp: vollog.debug("Process {}: invalid address {} in layer {}".format( - pid, excp.invalid_address, excp.layer_name)) + pid, excp.invalid_address, excp.layer_name)) continue for mapval in proc_layer.mapping(0x0, proc_layer.maximum_address, ignore_errors = True): - kpage, _, vpage, page_size, maplayer = mapval - - yield(0, ( - format_hints.Hex(kpage), - format_hints.Hex(vpage), - format_hints.Hex(page_size), - format_hints.Hex(offset))) - offset += page_size + offset, _, mapped_offset, mapped_size, maplayer = mapval + yield (0, ( + format_hints.Hex(offset), + format_hints.Hex(mapped_offset), + format_hints.Hex(mapped_size), + format_hints.Hex(offset))) + offset += mapped_size def run(self): filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)]) - return renderers.TreeGrid([ ("Virtual", format_hints.Hex),("Physical", format_hints.Hex), ("Size", format_hints.Hex), ("Offset", format_hints.Hex)], - self._generator( - pslist.PsList.list_processes(context = self.context, - layer_name = self.config['primary'], - symbol_table = self.config['nt_symbols'], - filter_func = filter_func))) \ No newline at end of file + return renderers.TreeGrid( + [("Virtual", format_hints.Hex), ("Physical", format_hints.Hex), ("Size", format_hints.Hex), + ("Offset", format_hints.Hex)], + self._generator( + pslist.PsList.list_processes(context = self.context, + layer_name = self.config['primary'], + symbol_table = self.config['nt_symbols'], + filter_func = filter_func))) diff --git a/volatility/framework/plugins/windows/strings.py b/volatility/framework/plugins/windows/strings.py index 47196cdea..d1aa794f0 100644 --- a/volatility/framework/plugins/windows/strings.py +++ b/volatility/framework/plugins/windows/strings.py @@ -4,8 +4,8 @@ import logging import re -from typing import Dict, Generator, List, Set, Tuple from os import path +from typing import Dict, Generator, List, Set, Tuple from volatility.framework import interfaces, renderers, exceptions from volatility.framework.configuration import requirements @@ -20,6 +20,7 @@ class Strings(interfaces.plugins.PluginInterface): """Reads output from the strings command and indicates which process(es) each string belongs to.""" strings_pattern = re.compile(rb"(?:\W*)([0-9]+)(?:\W*)(\w[\w\W]+)\n?") + @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ @@ -90,12 +91,12 @@ class Strings(interfaces.plugins.PluginInterface): if isinstance(layer, intel.Intel): # We don't care about errors, we just wanted chunks that map correctly for mapval in layer.mapping(0x0, layer.maximum_address, ignore_errors = True): - vpage, _, kpage, page_size, maplayer = mapval - for val in range(kpage, kpage + page_size, 0x1000): - cur_set = reverse_map.get(kpage >> 12, set()) - cur_set.add(("kernel", vpage)) - reverse_map[kpage >> 12] = cur_set - self._progress_callback((vpage * 100) / layer.maximum_address, "Creating reverse kernel map") + offset, _, mapped_offset, mapped_size, maplayer = mapval + for val in range(mapped_offset, mapped_offset + mapped_size, 0x1000): + cur_set = reverse_map.get(mapped_offset >> 12, set()) + cur_set.add(("kernel", offset)) + reverse_map[mapped_offset >> 12] = cur_set + self._progress_callback((offset * 100) / layer.maximum_address, "Creating reverse kernel map") # TODO: Include kernel modules @@ -113,13 +114,13 @@ class Strings(interfaces.plugins.PluginInterface): proc_layer = self.context.layers[proc_layer_name] if isinstance(proc_layer, linear.LinearlyMappedLayer): for mapval in proc_layer.mapping(0x0, proc_layer.maximum_address, ignore_errors = True): - kpage, _, vpage, page_size, maplayer = mapval - for val in range(kpage, kpage + page_size, 0x1000): - cur_set = reverse_map.get(kpage >> 12, set()) - cur_set.add(("Process {}".format(process.UniqueProcessId), vpage)) - reverse_map[kpage >> 12] = cur_set + mapped_offset, _, offset, mapped_size, maplayer = mapval + for val in range(mapped_offset, mapped_offset + mapped_size, 0x1000): + cur_set = reverse_map.get(mapped_offset >> 12, set()) + cur_set.add(("Process {}".format(process.UniqueProcessId), offset)) + reverse_map[mapped_offset >> 12] = cur_set # FIXME: make the progress for all processes, rather than per-process - self._progress_callback((vpage * 100) / layer.maximum_address, + self._progress_callback((offset * 100) / layer.maximum_address, "Creating mapping for task {}".format(process.UniqueProcessId)) return reverse_map