Merge pull request #554 from volatilityfoundation/feature/linux-mac-windows-unify-config

Feature/linux mac windows unify config
This commit is contained in:
ikelos
2021-08-27 22:20:43 +01:00
committed by GitHub
38 changed files with 157 additions and 145 deletions
+6 -4
View File
@@ -26,7 +26,8 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
requirements.ListRequirement(name = 'pid',
element_type = int,
@@ -35,7 +36,8 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
]
def _generator(self, tasks):
is_32bit = not symbols.symbol_table_is_64bit(self.context, self.config["vmlinux.symbol_table_name"])
vmlinux = self.context.modules[self.config["kernel"]]
is_32bit = not symbols.symbol_table_is_64bit(self.context, vmlinux.symbol_table_name)
if is_32bit:
pack_format = "I"
bash_json_file = "bash32"
@@ -90,7 +92,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
("Command", str)],
self._generator(
pslist.PsList.list_tasks(self.context,
self.config['vmlinux'],
self.config['kernel'],
filter_func = filter_func)))
def generate_timeline(self):
@@ -98,7 +100,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
for row in self._generator(
pslist.PsList.list_tasks(self.context,
self.config['vmlinux'],
self.config['kernel'],
filter_func = filter_func)):
_depth, row_data = row
description = f"{row_data[0]} ({row_data[1]}): \"{row_data[3]}\""
@@ -23,7 +23,8 @@ class Check_afinfo(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
]
# returns whether the symbol is found within the kernel (system.map) or not
@@ -61,7 +62,7 @@ class Check_afinfo(plugins.PluginInterface):
def _generator(self):
vmlinux = self.context.modules[self.config['vmlinux']]
vmlinux = self.context.modules[self.config['kernel']]
op_members = vmlinux.get_type('file_operations').members
seq_members = vmlinux.get_type('seq_operations').members
@@ -19,12 +19,13 @@ class Check_creds(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0))
]
def _generator(self):
vmlinux = self.context.modules[self.config['vmlinux']]
vmlinux = self.context.modules[self.config['kernel']]
type_task = vmlinux.get_type("task_struct")
@@ -22,13 +22,14 @@ class Check_idt(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
]
def _generator(self):
vmlinux = self.context.modules[self.config['vmlinux']]
vmlinux = self.context.modules[self.config['kernel']]
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
@@ -23,7 +23,8 @@ class Check_modules(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
]
@@ -60,11 +61,11 @@ class Check_modules(plugins.PluginInterface):
return ret
def _generator(self):
kset_modules = self.get_kset_modules(self.context, self.config['vmlinux'])
kset_modules = self.get_kset_modules(self.context, self.config['kernel'])
lsmod_modules = set(
str(utility.array_to_string(modules.name))
for modules in lsmod.Lsmod.list_modules(self.context, self.config['vmlinux']))
for modules in lsmod.Lsmod.list_modules(self.context, self.config['kernel']))
for mod_name in set(kset_modules.keys()).difference(lsmod_modules):
yield (0, (format_hints.Hex(kset_modules[mod_name]), str(mod_name)))
@@ -30,7 +30,8 @@ class Check_syscall(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
]
def _get_table_size_next_symbol(self, table_addr, ptr_sz, vmlinux):
@@ -101,7 +102,8 @@ class Check_syscall(plugins.PluginInterface):
# if we can't find the disassemble function then bail and rely on a different method
return 0
data = self.context.layers.read(self.config['vmlinux.layer_name'], func_addr, 6)
vmlinux = self.context.modules[self.config['kernel']]
data = self.context.layers.read(vmlinux.layer_name, func_addr, 6)
for (address, size, mnemonic, op_str) in md.disasm_lite(data, func_addr):
if mnemonic == 'CMP':
@@ -126,7 +128,7 @@ class Check_syscall(plugins.PluginInterface):
# TODO - add finding and parsing unistd.h once cached file enumeration is added
def _generator(self):
vmlinux = self.context.modules[self.config['vmlinux']]
vmlinux = self.context.modules[self.config['kernel']]
ptr_sz = vmlinux.get_type("pointer").size
if ptr_sz == 4:
+3 -2
View File
@@ -22,7 +22,8 @@ class Elfs(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
requirements.ListRequirement(name = 'pid',
description = 'Filter on specific process IDs',
@@ -56,5 +57,5 @@ class Elfs(plugins.PluginInterface):
("End", format_hints.Hex), ("File Path", str)],
self._generator(
pslist.PsList.list_tasks(self.context,
self.config['vmlinux'],
self.config['kernel'],
filter_func = filter_func)))
@@ -21,13 +21,14 @@ class Keyboard_notifiers(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0))
]
def _generator(self):
vmlinux = self.context.modules[self.config['vmlinux']]
vmlinux = self.context.modules[self.config['kernel']]
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
+30 -34
View File
@@ -2,17 +2,15 @@
# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0
#
import logging
from typing import List, Iterator, Tuple, Generator
from abc import ABC, abstractmethod
from enum import Enum
from typing import List, Iterator, Tuple, Generator
from volatility3.framework import renderers, interfaces, constants, contexts, class_subclasses
from volatility3.framework.configuration import requirements
from volatility3.framework.interfaces import plugins
from volatility3.framework.objects import utility
vollog = logging.getLogger(__name__)
@@ -53,14 +51,15 @@ class ABCKmsg(ABC):
)
def __init__(
self,
context: interfaces.context.ContextInterface,
config: interfaces.configuration.HierarchicalDict
self,
context: interfaces.context.ContextInterface,
config: interfaces.configuration.HierarchicalDict
):
self._context = context
self._config = config
self.layer_name = self._config['primary'] # type: ignore
symbol_table_name = self._config['vmlinux'] # type: ignore
vmlinux = context.modules[self._config['kernel']]
self.layer_name = kernel.layer_name # type: ignore
symbol_table_name = vmlinux.symbol_table_name # type: ignore
self.vmlinux = contexts.Module(context, symbol_table_name, self.layer_name, 0) # type: ignore
self.long_unsigned_int_size = self.vmlinux.get_type('long unsigned int').size
@@ -80,20 +79,17 @@ class ABCKmsg(ABC):
Yields:
kmsg records
"""
symbol_table_name = config['vmlinux'] # type: ignore
layer_name = config['primary'] # type: ignore
vmlinux = contexts.Module(context, symbol_table_name, layer_name, 0) # type: ignore
vmlinux = context.modules[config['kernel']]
kmsg_inst = None # type: ignore
for subclass in class_subclasses(cls):
if not subclass.symtab_checks(vmlinux=vmlinux):
if not subclass.symtab_checks(vmlinux = vmlinux):
vollog.log(constants.LOGLEVEL_VVVV,
"Kmsg implementation '%s' doesn't match this memory dump", subclass.__name__)
continue
vollog.log(constants.LOGLEVEL_VVVV, "Kmsg implementation '%s' matches!", subclass.__name__)
kmsg_inst = subclass(context=context, config=config)
kmsg_inst = subclass(context = context, config = config)
# More than one class could be executed for an specific kernel
# version i.e. Netfilter Ingress hooks
# We expect just one implementation to be executed for an specific kernel
@@ -120,7 +116,7 @@ class ABCKmsg(ABC):
def get_string(self, addr: int, length: int) -> str:
txt = self._context.layers[self.layer_name].read(addr, length) # type: ignore
return txt.decode(encoding='utf8', errors='replace')
return txt.decode(encoding = 'utf8', errors = 'replace')
def nsec_to_sec_str(self, nsec: int) -> str:
# See kernel/printk/printk.c:print_time()
@@ -172,6 +168,7 @@ class ABCKmsg(ABC):
vollog.debug(f"Facility {facility} unknown")
return str(facility)
class KmsgLegacy(ABCKmsg):
"""Linux kernels prior to v5.10, the ringbuffer is initially kept in
__log_buf, and log_buf is a pointer to the former. __log_buf is declared as
@@ -185,6 +182,7 @@ class KmsgLegacy(ABCKmsg):
consequently to the new buffer.
In that case, the original static buffer in __log_buf is unused.
"""
@classmethod
def symtab_checks(cls, vmlinux) -> bool:
return vmlinux.has_type('printk_log')
@@ -207,20 +205,20 @@ class KmsgLegacy(ABCKmsg):
yield " " + chunk.decode()
def run(self) -> Iterator[Tuple[str, str, str, str, str]]:
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name='log_buf')
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name = 'log_buf')
if log_buf_ptr == 0:
# This is weird, let's fallback to check the static ringbuffer.
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name='__log_buf').vol.offset
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name = '__log_buf').vol.offset
if log_buf_ptr == 0:
raise ValueError("Log buffer is not available")
log_first_idx = int(self.vmlinux.object_from_symbol(symbol_name='log_first_idx'))
log_first_idx = int(self.vmlinux.object_from_symbol(symbol_name = 'log_first_idx'))
cur_idx = log_first_idx
end_idx = None # We don't need log_next_idx here. See below msg.len == 0
while cur_idx != end_idx:
end_idx = log_first_idx
msg_offset = log_buf_ptr + cur_idx # type: ignore
msg = self.vmlinux.object(object_type='printk_log', offset=msg_offset)
msg = self.vmlinux.object(object_type = 'printk_log', offset = msg_offset)
if msg.len == 0:
# As per kernel/printk/printk.c:
# A length == 0 for the next message indicates a wrap-around to
@@ -273,6 +271,7 @@ class KmsgFiveTen(ABCKmsg):
See printk.c and printk_ringbuffer.c in kernel/printk/ folder for more
details.
"""
@classmethod
def symtab_checks(cls, vmlinux) -> bool:
return vmlinux.has_symbol('prb')
@@ -318,20 +317,20 @@ class KmsgFiveTen(ABCKmsg):
def run(self) -> Iterator[Tuple[str, str, str, str, str]]:
# static struct printk_ringbuffer *prb = &printk_rb_static;
ringbuffers = self.vmlinux.object_from_symbol(symbol_name='prb').dereference()
ringbuffers = self.vmlinux.object_from_symbol(symbol_name = 'prb').dereference()
desc_ring = ringbuffers.desc_ring
text_data_ring = ringbuffers.text_data_ring
desc_count = 1 << desc_ring.count_bits
desc_arr = self.vmlinux.object(object_type="array",
offset=desc_ring.descs,
subtype=self.vmlinux.get_type("prb_desc"),
count=desc_count)
info_arr = self.vmlinux.object(object_type="array",
offset=desc_ring.infos,
subtype=self.vmlinux.get_type("printk_info"),
count=desc_count)
desc_arr = self.vmlinux.object(object_type = "array",
offset = desc_ring.descs,
subtype = self.vmlinux.get_type("prb_desc"),
count = desc_count)
info_arr = self.vmlinux.object(object_type = "array",
offset = desc_ring.infos,
subtype = self.vmlinux.get_type("printk_info"),
count = desc_count)
# See kernel/printk/printk_ringbuffer.h
desc_state_var_bytes_sz = self.long_unsigned_int_size
@@ -371,15 +370,12 @@ class Kmsg(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(name='primary',
description="Memory layer for the kernel",
architectures=['Intel32', 'Intel64']),
requirements.SymbolTableRequirement(name='vmlinux',
description="Linux kernel symbols"),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ['Intel32', 'Intel64']),
]
def _generator(self) -> Iterator[Tuple[int, Tuple[str, str, str, str, str]]]:
for values in ABCKmsg.run_all(context=self.context, config=self.config):
for values in ABCKmsg.run_all(context = self.context, config = self.config):
yield (0, values)
def run(self):
+3 -2
View File
@@ -25,7 +25,8 @@ class Lsmod(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
]
@classmethod
@@ -54,7 +55,7 @@ class Lsmod(plugins.PluginInterface):
def _generator(self):
try:
for module in self.list_modules(self.context, self.config['vmlinux']):
for module in self.list_modules(self.context, self.config['kernel']):
mod_size = module.get_init_size() + module.get_core_size()
+4 -3
View File
@@ -24,7 +24,8 @@ class Lsof(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0)),
requirements.ListRequirement(name = 'pid',
@@ -34,7 +35,7 @@ class Lsof(plugins.PluginInterface):
]
def _generator(self, tasks):
vmlinux = self.context.modules[self.config['vmlinux']]
vmlinux = self.context.modules[self.config['kernel']]
symbol_table = None
for task in tasks:
@@ -56,5 +57,5 @@ class Lsof(plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("FD", int), ("Path", str)],
self._generator(
pslist.PsList.list_tasks(self.context,
self.config['vmlinux'],
self.config['kernel'],
filter_func = filter_func)))
@@ -20,7 +20,8 @@ class Malfind(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
requirements.ListRequirement(name = 'pid',
description = 'Filter on specific process IDs',
@@ -45,8 +46,8 @@ class Malfind(interfaces.plugins.PluginInterface):
def _generator(self, tasks):
# determine if we're on a 32 or 64 bit kernel
if self.context.symbol_space.get_type(
self.config["vmlinux.symbol_table_name"] + constants.BANG + "pointer").size == 4:
vmlinux = self.context.modules[self.config['kernel']]
if self.context.symbol_space.get_type(vmlinux.symbol_table_name + constants.BANG + "pointer").size == 4:
is_32bit_arch = True
else:
is_32bit_arch = False
+3 -2
View File
@@ -21,7 +21,8 @@ class Maps(plugins.PluginInterface):
def get_requirements(cls):
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
requirements.ListRequirement(name = 'pid',
description = 'Filter on specific process IDs',
@@ -65,5 +66,5 @@ class Maps(plugins.PluginInterface):
("File Path", str)],
self._generator(
pslist.PsList.list_tasks(self.context,
self.config['vmlinux'],
self.config['kernel'],
filter_func = filter_func)))
@@ -18,7 +18,8 @@ class PsList(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.ListRequirement(name = 'pid',
description = 'Filter on specific process IDs',
element_type = int,
@@ -49,7 +50,7 @@ class PsList(interfaces.plugins.PluginInterface):
def _generator(self):
for task in self.list_tasks(self.context,
self.config['vmlinux'],
self.config['kernel'],
filter_func = self.create_pid_filter(self.config.get('pid', None))):
pid = task.pid
ppid = 0
@@ -34,8 +34,8 @@ class PsTree(pslist.PsList):
def _generator(self):
"""Generates the."""
for proc in self.list_tasks(self.context, self.config['vmlinux.layer_name'],
self.config['vmlinux.symbol_table_name']):
vmlinux = self.context.modules[self.config['kernel']]
for proc in self.list_tasks(self.context, vmlinux.layer_name, vmlinux.symbol_table_name):
self._processes[proc.pid] = proc
# Build the child/level maps
@@ -24,13 +24,14 @@ class tty_check(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0))
]
def _generator(self):
vmlinux = self.context.modules[self.config['vmlinux']]
vmlinux = self.context.modules[self.config['kernel']]
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
+7 -6
View File
@@ -25,7 +25,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
requirements.ListRequirement(name = 'pid',
@@ -35,7 +35,8 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
]
def _generator(self, tasks):
is_32bit = not symbols.symbol_table_is_64bit(self.context, self.config["darwin.symbol_table_name"])
darwin = self.context.modules[self.config['kernel']]
is_32bit = not symbols.symbol_table_is_64bit(self.context, darwin.symbol_table_name)
if is_32bit:
pack_format = "I"
bash_json_file = "bash32"
@@ -65,7 +66,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
for address in proc_layer.scan(self.context,
scanners.BytesScanner(b"#"),
sections = task.get_process_memory_sections(self.context,
self.config['darwin'],
self.config['kernel'],
rw_no_file = True)):
bang_addrs.append(struct.pack(pack_format, address))
@@ -74,7 +75,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
for address, _ in proc_layer.scan(self.context,
scanners.MultiStringScanner(bang_addrs),
sections = task.get_process_memory_sections(self.context,
self.config['darwin'],
self.config['kernel'],
rw_no_file = True)):
hist = self.context.object(bash_table_name + constants.BANG + "hist_entry",
offset = address - ts_offset,
@@ -94,7 +95,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
("Command", str)],
self._generator(
list_tasks(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func)))
def generate_timeline(self):
@@ -103,7 +104,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
for row in self._generator(
list_tasks(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func)):
_depth, row_data = row
description = f"{row_data[0]} ({row_data[1]}): \"{row_data[3]}\""
@@ -23,16 +23,16 @@ class Check_syscall(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
]
def _generator(self):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
@@ -54,7 +54,7 @@ class Check_syscall(plugins.PluginInterface):
continue
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers,
call_addr, self.config['darwin'])
call_addr, self.config['kernel'])
yield (0, (format_hints.Hex(table.vol.offset), "SysCall", i, format_hints.Hex(call_addr), module_name,
symbol_name))
@@ -25,7 +25,7 @@ class Check_sysctl(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
@@ -113,9 +113,9 @@ class Check_sysctl(plugins.PluginInterface):
break
def _generator(self):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
@@ -128,7 +128,7 @@ class Check_sysctl(plugins.PluginInterface):
continue
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, check_addr,
self.config['darwin'])
self.config['kernel'])
yield (0, (name, sysctl.oid_number, sysctl.get_perms(), format_hints.Hex(check_addr), val, module_name,
symbol_name))
@@ -24,16 +24,16 @@ class Check_trap_table(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
]
def _generator(self):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
@@ -49,7 +49,7 @@ class Check_trap_table(plugins.PluginInterface):
continue
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, call_addr,
self.config['darwin'])
self.config['kernel'])
yield (0, (format_hints.Hex(table.vol.offset), "TrapTable", i, format_hints.Hex(call_addr), module_name,
symbol_name))
@@ -16,13 +16,13 @@ class Ifconfig(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0))
]
def _generator(self):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
try:
list_head = kernel.object_from_symbol(symbol_name = "ifnet_head")
@@ -18,7 +18,7 @@ class Kauth_listeners(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
@@ -31,13 +31,13 @@ class Kauth_listeners(interfaces.plugins.PluginInterface):
"""
Enumerates the listeners for each kauth scope
"""
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
for scope in kauth_scopes.Kauth_scopes.list_kauth_scopes(self.context, self.config['darwin']):
for scope in kauth_scopes.Kauth_scopes.list_kauth_scopes(self.context, self.config['kernel']):
scope_name = utility.pointer_to_string(scope.ks_identifier, 128)
@@ -47,7 +47,7 @@ class Kauth_listeners(interfaces.plugins.PluginInterface):
continue
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, callback,
self.config['darwin'])
self.config['kernel'])
yield (0, (scope_name, format_hints.Hex(listener.kll_idata), format_hints.Hex(callback), module_name,
symbol_name))
@@ -2,7 +2,7 @@
# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0
#
import logging
from typing import Iterable, Callable, Tuple
from typing import Iterable, Callable
from volatility3.framework import renderers, interfaces
from volatility3.framework.configuration import requirements
@@ -23,7 +23,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
@@ -34,9 +34,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
context: interfaces.context.ContextInterface,
kernel_module_name: str,
filter_func: Callable[[int], bool] = lambda _: False) -> \
Iterable[Tuple[interfaces.objects.ObjectInterface,
interfaces.objects.ObjectInterface,
interfaces.objects.ObjectInterface]]:
Iterable[interfaces.objects.ObjectInterface]:
"""
Enumerates the registered kauth scopes and yields each object
Uses smear-safe enumeration API
@@ -50,20 +48,20 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
yield scope
def _generator(self):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
for scope in self.list_kauth_scopes(self.context, self.config['darwin']):
for scope in self.list_kauth_scopes(self.context, self.config['kernel']):
callback = scope.ks_callback
if callback == 0:
continue
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, callback,
self.config['darwin'])
self.config['kernel'])
identifier = utility.pointer_to_string(scope.ks_identifier, 128)
+2 -2
View File
@@ -48,7 +48,7 @@ class Kevents(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 2, 0)),
@@ -148,7 +148,7 @@ class Kevents(interfaces.plugins.PluginInterface):
filter_func = pslist.PsList.create_pid_filter(self.config.get('pid', None))
for task_name, pid, kn in self.list_kernel_events(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func):
filter_index = kn.kn_kevent.filter * -1
@@ -23,7 +23,7 @@ class List_Files(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'mount', plugin = mount.Mount, version = (2, 0, 0)),
]
@@ -165,7 +165,7 @@ class List_Files(plugins.PluginInterface):
yield vnode, full_path
def _generator(self):
for vnode, full_path in self.list_files(self.context, self.config['darwin']):
for vnode, full_path in self.list_files(self.context, self.config['kernel']):
yield (0, (format_hints.Hex(vnode), full_path))
+2 -2
View File
@@ -22,7 +22,7 @@ class Lsmod(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
]
@@ -76,7 +76,7 @@ class Lsmod(plugins.PluginInterface):
return
def _generator(self):
for module in self.list_modules(self.context, self.config['darwin']):
for module in self.list_modules(self.context, self.config['kernel']):
mod_name = utility.array_to_string(module.name)
mod_size = module.size
+5 -4
View File
@@ -21,7 +21,7 @@ class Lsof(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
@@ -32,11 +32,12 @@ class Lsof(plugins.PluginInterface):
]
def _generator(self, tasks):
darwin = self.context.modules[self.config['kernel']]
for task in tasks:
pid = task.p_pid
for _, filepath, fd in mac.MacUtilities.files_descriptors_for_process(self.context, self.config[
'darwin.symbol_table_name'],
for _, filepath, fd in mac.MacUtilities.files_descriptors_for_process(self.context,
darwin.symbol_table_name,
task):
if filepath and len(filepath) > 0:
yield (0, (pid, fd, filepath))
@@ -48,5 +49,5 @@ class Lsof(plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("File Descriptor", int), ("File Path", str)],
self._generator(
list_tasks(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func)))
+4 -4
View File
@@ -18,7 +18,7 @@ class Malfind(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
requirements.ListRequirement(name = 'pid',
@@ -38,13 +38,13 @@ class Malfind(interfaces.plugins.PluginInterface):
proc_layer = self.context.layers[proc_layer_name]
for vma in task.get_map_iter():
if not vma.is_suspicious(self.context, self.context.modules[self.config['darwin']].symbol_table_name):
if not vma.is_suspicious(self.context, self.context.modules[self.config['kernel']].symbol_table_name):
data = proc_layer.read(vma.links.start, 64, pad = True)
yield vma, data
def _generator(self, tasks):
# determine if we're on a 32 or 64 bit kernel
if self.context.modules[self.config['darwin']].get_type("pointer").size == 4:
if self.context.modules[self.config['kernel']].get_type("pointer").size == 4:
is_32bit_arch = True
else:
is_32bit_arch = False
@@ -72,5 +72,5 @@ class Malfind(interfaces.plugins.PluginInterface):
("Disasm", interfaces.renderers.Disassembly)],
self._generator(
list_tasks(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func)))
+2 -2
View File
@@ -21,7 +21,7 @@ class Mount(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
]
@@ -46,7 +46,7 @@ class Mount(plugins.PluginInterface):
yield mount
def _generator(self):
for mount in self.list_mounts(self.context, self.config['darwin']):
for mount in self.list_mounts(self.context, self.config['kernel']):
vfs = mount.mnt_vfsstat
device_name = utility.array_to_string(vfs.f_mntonname)
mount_point = utility.array_to_string(vfs.f_mntfromname)
+3 -3
View File
@@ -24,7 +24,7 @@ class Netstat(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
@@ -74,7 +74,7 @@ class Netstat(plugins.PluginInterface):
continue
if not context.layers[task.vol.native_layer_name].is_valid(socket.vol.offset,
socket.vol.size):
socket.vol.size):
continue
yield task_name, pid, socket
@@ -83,7 +83,7 @@ class Netstat(plugins.PluginInterface):
filter_func = pslist.PsList.create_pid_filter(self.config.get('pid', None))
for task_name, pid, socket in self.list_sockets(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func):
family = socket.get_family()
@@ -17,7 +17,7 @@ class Maps(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
requirements.ListRequirement(name = 'pid',
@@ -32,7 +32,7 @@ class Maps(interfaces.plugins.PluginInterface):
process_pid = task.p_pid
for vma in task.get_map_iter():
path = vma.get_path(self.context, self.context.modules[self.config['darwin']].symbol_table_name)
path = vma.get_path(self.context, self.context.modules[self.config['kernel']].symbol_table_name)
if path == "":
path = vma.get_special_path()
@@ -47,5 +47,5 @@ class Maps(interfaces.plugins.PluginInterface):
("End", format_hints.Hex), ("Protection", str), ("Map Name", str)],
self._generator(
list_tasks(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func)))
+2 -2
View File
@@ -19,7 +19,7 @@ class Psaux(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
requirements.ListRequirement(name = 'pid',
@@ -96,5 +96,5 @@ class Psaux(plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Argc", int), ("Arguments", str)],
self._generator(
list_tasks(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = filter_func)))
+2 -2
View File
@@ -23,7 +23,7 @@ class PsList(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)),
requirements.ChoiceRequirement(name = 'pslist_method',
@@ -89,7 +89,7 @@ class PsList(interfaces.plugins.PluginInterface):
list_tasks = self.get_list_tasks(self.config.get('pslist_method', self.pslist_methods[0]))
for task in list_tasks(self.context,
self.config['darwin'],
self.config['kernel'],
filter_func = self.create_pid_filter(self.config.get('pid', None))):
pid = task.p_pid
ppid = task.p_ppid
+2 -2
View File
@@ -24,7 +24,7 @@ class PsTree(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0))
]
@@ -48,7 +48,7 @@ class PsTree(plugins.PluginInterface):
"""Generates the tree list of processes"""
list_tasks = pslist.PsList.get_list_tasks(self.config.get('pslist_method', pslist.PsList.pslist_methods[0]))
for proc in list_tasks(self.context, self.config['darwin']):
for proc in list_tasks(self.context, self.config['kernel']):
self._processes[proc.p_pid] = proc
# Build the child/level maps
@@ -24,16 +24,16 @@ class Socket_filters(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
]
def _generator(self):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
+4 -4
View File
@@ -23,16 +23,16 @@ class Timers(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 3, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
]
def _generator(self):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
@@ -69,7 +69,7 @@ class Timers(plugins.PluginInterface):
entry_time = -1
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, handler,
self.config['darwin'])
self.config['kernel'])
yield (0, (format_hints.Hex(handler), format_hints.Hex(timer.param0), format_hints.Hex(timer.param1),
timer.deadline, entry_time, module_name, symbol_name))
@@ -25,14 +25,14 @@ class Trustedbsd(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 3, 0)),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
]
def _generator(self, mods: Iterator[Any]):
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
@@ -65,7 +65,7 @@ class Trustedbsd(plugins.PluginInterface):
continue
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, call_addr,
self.config['darwin'])
self.config['kernel'])
yield (0, (check, ent_name, format_hints.Hex(call_addr), module_name, symbol_name))
@@ -73,4 +73,4 @@ class Trustedbsd(plugins.PluginInterface):
return renderers.TreeGrid([("Member", str), ("Policy Name", str), ("Handler Address", format_hints.Hex),
("Handler Module", str), ("Handler Symbol", str)],
self._generator(
lsmod.Lsmod.list_modules(self.context, self.config['darwin'])))
lsmod.Lsmod.list_modules(self.context, self.config['kernel'])))
@@ -20,7 +20,7 @@ class VFSevents(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
architectures = ["Intel32", "Intel64"]),
]
@@ -30,7 +30,7 @@ class VFSevents(interfaces.plugins.PluginInterface):
Also lists which event(s) a process is registered for
"""
kernel = self.context.modules[self.config['darwin']]
kernel = self.context.modules[self.config['kernel']]
watcher_table = kernel.object_from_symbol("watcher_table")