mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 05:24:52 +02:00
Merge pull request #554 from volatilityfoundation/feature/linux-mac-windows-unify-config
Feature/linux mac windows unify config
This commit is contained in:
@@ -26,7 +26,8 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
element_type = int,
|
||||
@@ -35,7 +36,8 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
]
|
||||
|
||||
def _generator(self, tasks):
|
||||
is_32bit = not symbols.symbol_table_is_64bit(self.context, self.config["vmlinux.symbol_table_name"])
|
||||
vmlinux = self.context.modules[self.config["kernel"]]
|
||||
is_32bit = not symbols.symbol_table_is_64bit(self.context, vmlinux.symbol_table_name)
|
||||
if is_32bit:
|
||||
pack_format = "I"
|
||||
bash_json_file = "bash32"
|
||||
@@ -90,7 +92,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
("Command", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
def generate_timeline(self):
|
||||
@@ -98,7 +100,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
|
||||
for row in self._generator(
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)):
|
||||
_depth, row_data = row
|
||||
description = f"{row_data[0]} ({row_data[1]}): \"{row_data[3]}\""
|
||||
|
||||
@@ -23,7 +23,8 @@ class Check_afinfo(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
]
|
||||
|
||||
# returns whether the symbol is found within the kernel (system.map) or not
|
||||
@@ -61,7 +62,7 @@ class Check_afinfo(plugins.PluginInterface):
|
||||
|
||||
def _generator(self):
|
||||
|
||||
vmlinux = self.context.modules[self.config['vmlinux']]
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
|
||||
op_members = vmlinux.get_type('file_operations').members
|
||||
seq_members = vmlinux.get_type('seq_operations').members
|
||||
|
||||
@@ -19,12 +19,13 @@ class Check_creds(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
vmlinux = self.context.modules[self.config['vmlinux']]
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
|
||||
type_task = vmlinux.get_type("task_struct")
|
||||
|
||||
|
||||
@@ -22,13 +22,14 @@ class Check_idt(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
vmlinux = self.context.modules[self.config['vmlinux']]
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
|
||||
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
|
||||
|
||||
|
||||
@@ -23,7 +23,8 @@ class Check_modules(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
@@ -60,11 +61,11 @@ class Check_modules(plugins.PluginInterface):
|
||||
return ret
|
||||
|
||||
def _generator(self):
|
||||
kset_modules = self.get_kset_modules(self.context, self.config['vmlinux'])
|
||||
kset_modules = self.get_kset_modules(self.context, self.config['kernel'])
|
||||
|
||||
lsmod_modules = set(
|
||||
str(utility.array_to_string(modules.name))
|
||||
for modules in lsmod.Lsmod.list_modules(self.context, self.config['vmlinux']))
|
||||
for modules in lsmod.Lsmod.list_modules(self.context, self.config['kernel']))
|
||||
|
||||
for mod_name in set(kset_modules.keys()).difference(lsmod_modules):
|
||||
yield (0, (format_hints.Hex(kset_modules[mod_name]), str(mod_name)))
|
||||
|
||||
@@ -30,7 +30,8 @@ class Check_syscall(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
]
|
||||
|
||||
def _get_table_size_next_symbol(self, table_addr, ptr_sz, vmlinux):
|
||||
@@ -101,7 +102,8 @@ class Check_syscall(plugins.PluginInterface):
|
||||
# if we can't find the disassemble function then bail and rely on a different method
|
||||
return 0
|
||||
|
||||
data = self.context.layers.read(self.config['vmlinux.layer_name'], func_addr, 6)
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
data = self.context.layers.read(vmlinux.layer_name, func_addr, 6)
|
||||
|
||||
for (address, size, mnemonic, op_str) in md.disasm_lite(data, func_addr):
|
||||
if mnemonic == 'CMP':
|
||||
@@ -126,7 +128,7 @@ class Check_syscall(plugins.PluginInterface):
|
||||
|
||||
# TODO - add finding and parsing unistd.h once cached file enumeration is added
|
||||
def _generator(self):
|
||||
vmlinux = self.context.modules[self.config['vmlinux']]
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
|
||||
ptr_sz = vmlinux.get_type("pointer").size
|
||||
if ptr_sz == 4:
|
||||
|
||||
@@ -22,7 +22,8 @@ class Elfs(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
description = 'Filter on specific process IDs',
|
||||
@@ -56,5 +57,5 @@ class Elfs(plugins.PluginInterface):
|
||||
("End", format_hints.Hex), ("File Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -21,13 +21,14 @@ class Keyboard_notifiers(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
|
||||
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
vmlinux = self.context.modules[self.config['vmlinux']]
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
|
||||
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
|
||||
|
||||
|
||||
@@ -2,17 +2,15 @@
|
||||
# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0
|
||||
#
|
||||
import logging
|
||||
from typing import List, Iterator, Tuple, Generator
|
||||
|
||||
from abc import ABC, abstractmethod
|
||||
from enum import Enum
|
||||
from typing import List, Iterator, Tuple, Generator
|
||||
|
||||
from volatility3.framework import renderers, interfaces, constants, contexts, class_subclasses
|
||||
from volatility3.framework.configuration import requirements
|
||||
from volatility3.framework.interfaces import plugins
|
||||
from volatility3.framework.objects import utility
|
||||
|
||||
|
||||
vollog = logging.getLogger(__name__)
|
||||
|
||||
|
||||
@@ -53,14 +51,15 @@ class ABCKmsg(ABC):
|
||||
)
|
||||
|
||||
def __init__(
|
||||
self,
|
||||
context: interfaces.context.ContextInterface,
|
||||
config: interfaces.configuration.HierarchicalDict
|
||||
self,
|
||||
context: interfaces.context.ContextInterface,
|
||||
config: interfaces.configuration.HierarchicalDict
|
||||
):
|
||||
self._context = context
|
||||
self._config = config
|
||||
self.layer_name = self._config['primary'] # type: ignore
|
||||
symbol_table_name = self._config['vmlinux'] # type: ignore
|
||||
vmlinux = context.modules[self._config['kernel']]
|
||||
self.layer_name = kernel.layer_name # type: ignore
|
||||
symbol_table_name = vmlinux.symbol_table_name # type: ignore
|
||||
self.vmlinux = contexts.Module(context, symbol_table_name, self.layer_name, 0) # type: ignore
|
||||
self.long_unsigned_int_size = self.vmlinux.get_type('long unsigned int').size
|
||||
|
||||
@@ -80,20 +79,17 @@ class ABCKmsg(ABC):
|
||||
Yields:
|
||||
kmsg records
|
||||
"""
|
||||
|
||||
symbol_table_name = config['vmlinux'] # type: ignore
|
||||
layer_name = config['primary'] # type: ignore
|
||||
vmlinux = contexts.Module(context, symbol_table_name, layer_name, 0) # type: ignore
|
||||
vmlinux = context.modules[config['kernel']]
|
||||
|
||||
kmsg_inst = None # type: ignore
|
||||
for subclass in class_subclasses(cls):
|
||||
if not subclass.symtab_checks(vmlinux=vmlinux):
|
||||
if not subclass.symtab_checks(vmlinux = vmlinux):
|
||||
vollog.log(constants.LOGLEVEL_VVVV,
|
||||
"Kmsg implementation '%s' doesn't match this memory dump", subclass.__name__)
|
||||
continue
|
||||
|
||||
vollog.log(constants.LOGLEVEL_VVVV, "Kmsg implementation '%s' matches!", subclass.__name__)
|
||||
kmsg_inst = subclass(context=context, config=config)
|
||||
kmsg_inst = subclass(context = context, config = config)
|
||||
# More than one class could be executed for an specific kernel
|
||||
# version i.e. Netfilter Ingress hooks
|
||||
# We expect just one implementation to be executed for an specific kernel
|
||||
@@ -120,7 +116,7 @@ class ABCKmsg(ABC):
|
||||
|
||||
def get_string(self, addr: int, length: int) -> str:
|
||||
txt = self._context.layers[self.layer_name].read(addr, length) # type: ignore
|
||||
return txt.decode(encoding='utf8', errors='replace')
|
||||
return txt.decode(encoding = 'utf8', errors = 'replace')
|
||||
|
||||
def nsec_to_sec_str(self, nsec: int) -> str:
|
||||
# See kernel/printk/printk.c:print_time()
|
||||
@@ -172,6 +168,7 @@ class ABCKmsg(ABC):
|
||||
vollog.debug(f"Facility {facility} unknown")
|
||||
return str(facility)
|
||||
|
||||
|
||||
class KmsgLegacy(ABCKmsg):
|
||||
"""Linux kernels prior to v5.10, the ringbuffer is initially kept in
|
||||
__log_buf, and log_buf is a pointer to the former. __log_buf is declared as
|
||||
@@ -185,6 +182,7 @@ class KmsgLegacy(ABCKmsg):
|
||||
consequently to the new buffer.
|
||||
In that case, the original static buffer in __log_buf is unused.
|
||||
"""
|
||||
|
||||
@classmethod
|
||||
def symtab_checks(cls, vmlinux) -> bool:
|
||||
return vmlinux.has_type('printk_log')
|
||||
@@ -207,20 +205,20 @@ class KmsgLegacy(ABCKmsg):
|
||||
yield " " + chunk.decode()
|
||||
|
||||
def run(self) -> Iterator[Tuple[str, str, str, str, str]]:
|
||||
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name='log_buf')
|
||||
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name = 'log_buf')
|
||||
if log_buf_ptr == 0:
|
||||
# This is weird, let's fallback to check the static ringbuffer.
|
||||
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name='__log_buf').vol.offset
|
||||
log_buf_ptr = self.vmlinux.object_from_symbol(symbol_name = '__log_buf').vol.offset
|
||||
if log_buf_ptr == 0:
|
||||
raise ValueError("Log buffer is not available")
|
||||
|
||||
log_first_idx = int(self.vmlinux.object_from_symbol(symbol_name='log_first_idx'))
|
||||
log_first_idx = int(self.vmlinux.object_from_symbol(symbol_name = 'log_first_idx'))
|
||||
cur_idx = log_first_idx
|
||||
end_idx = None # We don't need log_next_idx here. See below msg.len == 0
|
||||
while cur_idx != end_idx:
|
||||
end_idx = log_first_idx
|
||||
msg_offset = log_buf_ptr + cur_idx # type: ignore
|
||||
msg = self.vmlinux.object(object_type='printk_log', offset=msg_offset)
|
||||
msg = self.vmlinux.object(object_type = 'printk_log', offset = msg_offset)
|
||||
if msg.len == 0:
|
||||
# As per kernel/printk/printk.c:
|
||||
# A length == 0 for the next message indicates a wrap-around to
|
||||
@@ -273,6 +271,7 @@ class KmsgFiveTen(ABCKmsg):
|
||||
See printk.c and printk_ringbuffer.c in kernel/printk/ folder for more
|
||||
details.
|
||||
"""
|
||||
|
||||
@classmethod
|
||||
def symtab_checks(cls, vmlinux) -> bool:
|
||||
return vmlinux.has_symbol('prb')
|
||||
@@ -318,20 +317,20 @@ class KmsgFiveTen(ABCKmsg):
|
||||
|
||||
def run(self) -> Iterator[Tuple[str, str, str, str, str]]:
|
||||
# static struct printk_ringbuffer *prb = &printk_rb_static;
|
||||
ringbuffers = self.vmlinux.object_from_symbol(symbol_name='prb').dereference()
|
||||
ringbuffers = self.vmlinux.object_from_symbol(symbol_name = 'prb').dereference()
|
||||
|
||||
desc_ring = ringbuffers.desc_ring
|
||||
text_data_ring = ringbuffers.text_data_ring
|
||||
|
||||
desc_count = 1 << desc_ring.count_bits
|
||||
desc_arr = self.vmlinux.object(object_type="array",
|
||||
offset=desc_ring.descs,
|
||||
subtype=self.vmlinux.get_type("prb_desc"),
|
||||
count=desc_count)
|
||||
info_arr = self.vmlinux.object(object_type="array",
|
||||
offset=desc_ring.infos,
|
||||
subtype=self.vmlinux.get_type("printk_info"),
|
||||
count=desc_count)
|
||||
desc_arr = self.vmlinux.object(object_type = "array",
|
||||
offset = desc_ring.descs,
|
||||
subtype = self.vmlinux.get_type("prb_desc"),
|
||||
count = desc_count)
|
||||
info_arr = self.vmlinux.object(object_type = "array",
|
||||
offset = desc_ring.infos,
|
||||
subtype = self.vmlinux.get_type("printk_info"),
|
||||
count = desc_count)
|
||||
|
||||
# See kernel/printk/printk_ringbuffer.h
|
||||
desc_state_var_bytes_sz = self.long_unsigned_int_size
|
||||
@@ -371,15 +370,12 @@ class Kmsg(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(name='primary',
|
||||
description="Memory layer for the kernel",
|
||||
architectures=['Intel32', 'Intel64']),
|
||||
requirements.SymbolTableRequirement(name='vmlinux',
|
||||
description="Linux kernel symbols"),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ['Intel32', 'Intel64']),
|
||||
]
|
||||
|
||||
def _generator(self) -> Iterator[Tuple[int, Tuple[str, str, str, str, str]]]:
|
||||
for values in ABCKmsg.run_all(context=self.context, config=self.config):
|
||||
for values in ABCKmsg.run_all(context = self.context, config = self.config):
|
||||
yield (0, values)
|
||||
|
||||
def run(self):
|
||||
|
||||
@@ -25,7 +25,8 @@ class Lsmod(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
]
|
||||
|
||||
@classmethod
|
||||
@@ -54,7 +55,7 @@ class Lsmod(plugins.PluginInterface):
|
||||
|
||||
def _generator(self):
|
||||
try:
|
||||
for module in self.list_modules(self.context, self.config['vmlinux']):
|
||||
for module in self.list_modules(self.context, self.config['kernel']):
|
||||
|
||||
mod_size = module.get_init_size() + module.get_core_size()
|
||||
|
||||
|
||||
@@ -24,7 +24,8 @@ class Lsof(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
|
||||
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
@@ -34,7 +35,7 @@ class Lsof(plugins.PluginInterface):
|
||||
]
|
||||
|
||||
def _generator(self, tasks):
|
||||
vmlinux = self.context.modules[self.config['vmlinux']]
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
|
||||
symbol_table = None
|
||||
for task in tasks:
|
||||
@@ -56,5 +57,5 @@ class Lsof(plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("FD", int), ("Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -20,7 +20,8 @@ class Malfind(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
description = 'Filter on specific process IDs',
|
||||
@@ -45,8 +46,8 @@ class Malfind(interfaces.plugins.PluginInterface):
|
||||
|
||||
def _generator(self, tasks):
|
||||
# determine if we're on a 32 or 64 bit kernel
|
||||
if self.context.symbol_space.get_type(
|
||||
self.config["vmlinux.symbol_table_name"] + constants.BANG + "pointer").size == 4:
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
if self.context.symbol_space.get_type(vmlinux.symbol_table_name + constants.BANG + "pointer").size == 4:
|
||||
is_32bit_arch = True
|
||||
else:
|
||||
is_32bit_arch = False
|
||||
|
||||
@@ -21,7 +21,8 @@ class Maps(plugins.PluginInterface):
|
||||
def get_requirements(cls):
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
description = 'Filter on specific process IDs',
|
||||
@@ -65,5 +66,5 @@ class Maps(plugins.PluginInterface):
|
||||
("File Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -18,7 +18,8 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
description = 'Filter on specific process IDs',
|
||||
element_type = int,
|
||||
@@ -49,7 +50,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
|
||||
def _generator(self):
|
||||
for task in self.list_tasks(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['kernel'],
|
||||
filter_func = self.create_pid_filter(self.config.get('pid', None))):
|
||||
pid = task.pid
|
||||
ppid = 0
|
||||
|
||||
@@ -34,8 +34,8 @@ class PsTree(pslist.PsList):
|
||||
|
||||
def _generator(self):
|
||||
"""Generates the."""
|
||||
for proc in self.list_tasks(self.context, self.config['vmlinux.layer_name'],
|
||||
self.config['vmlinux.symbol_table_name']):
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
for proc in self.list_tasks(self.context, vmlinux.layer_name, vmlinux.symbol_table_name):
|
||||
self._processes[proc.pid] = proc
|
||||
|
||||
# Build the child/level maps
|
||||
|
||||
@@ -24,13 +24,14 @@ class tty_check(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'vmlinux', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Linux kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
|
||||
requirements.VersionRequirement(name = 'linuxutils', component = linux.LinuxUtilities, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
vmlinux = self.context.modules[self.config['vmlinux']]
|
||||
vmlinux = self.context.modules[self.config['kernel']]
|
||||
|
||||
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
|
||||
|
||||
|
||||
@@ -25,7 +25,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
@@ -35,7 +35,8 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
]
|
||||
|
||||
def _generator(self, tasks):
|
||||
is_32bit = not symbols.symbol_table_is_64bit(self.context, self.config["darwin.symbol_table_name"])
|
||||
darwin = self.context.modules[self.config['kernel']]
|
||||
is_32bit = not symbols.symbol_table_is_64bit(self.context, darwin.symbol_table_name)
|
||||
if is_32bit:
|
||||
pack_format = "I"
|
||||
bash_json_file = "bash32"
|
||||
@@ -65,7 +66,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
for address in proc_layer.scan(self.context,
|
||||
scanners.BytesScanner(b"#"),
|
||||
sections = task.get_process_memory_sections(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
rw_no_file = True)):
|
||||
bang_addrs.append(struct.pack(pack_format, address))
|
||||
|
||||
@@ -74,7 +75,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
for address, _ in proc_layer.scan(self.context,
|
||||
scanners.MultiStringScanner(bang_addrs),
|
||||
sections = task.get_process_memory_sections(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
rw_no_file = True)):
|
||||
hist = self.context.object(bash_table_name + constants.BANG + "hist_entry",
|
||||
offset = address - ts_offset,
|
||||
@@ -94,7 +95,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
("Command", str)],
|
||||
self._generator(
|
||||
list_tasks(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
def generate_timeline(self):
|
||||
@@ -103,7 +104,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
|
||||
for row in self._generator(
|
||||
list_tasks(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)):
|
||||
_depth, row_data = row
|
||||
description = f"{row_data[0]} ({row_data[1]}): \"{row_data[3]}\""
|
||||
|
||||
@@ -23,16 +23,16 @@ class Check_syscall(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
@@ -54,7 +54,7 @@ class Check_syscall(plugins.PluginInterface):
|
||||
continue
|
||||
|
||||
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers,
|
||||
call_addr, self.config['darwin'])
|
||||
call_addr, self.config['kernel'])
|
||||
|
||||
yield (0, (format_hints.Hex(table.vol.offset), "SysCall", i, format_hints.Hex(call_addr), module_name,
|
||||
symbol_name))
|
||||
|
||||
@@ -25,7 +25,7 @@ class Check_sysctl(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
@@ -113,9 +113,9 @@ class Check_sysctl(plugins.PluginInterface):
|
||||
break
|
||||
|
||||
def _generator(self):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
@@ -128,7 +128,7 @@ class Check_sysctl(plugins.PluginInterface):
|
||||
continue
|
||||
|
||||
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, check_addr,
|
||||
self.config['darwin'])
|
||||
self.config['kernel'])
|
||||
|
||||
yield (0, (name, sysctl.oid_number, sysctl.get_perms(), format_hints.Hex(check_addr), val, module_name,
|
||||
symbol_name))
|
||||
|
||||
@@ -24,16 +24,16 @@ class Check_trap_table(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
@@ -49,7 +49,7 @@ class Check_trap_table(plugins.PluginInterface):
|
||||
continue
|
||||
|
||||
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, call_addr,
|
||||
self.config['darwin'])
|
||||
self.config['kernel'])
|
||||
|
||||
yield (0, (format_hints.Hex(table.vol.offset), "TrapTable", i, format_hints.Hex(call_addr), module_name,
|
||||
symbol_name))
|
||||
|
||||
@@ -16,13 +16,13 @@ class Ifconfig(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
try:
|
||||
list_head = kernel.object_from_symbol(symbol_name = "ifnet_head")
|
||||
|
||||
@@ -18,7 +18,7 @@ class Kauth_listeners(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)),
|
||||
@@ -31,13 +31,13 @@ class Kauth_listeners(interfaces.plugins.PluginInterface):
|
||||
"""
|
||||
Enumerates the listeners for each kauth scope
|
||||
"""
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
for scope in kauth_scopes.Kauth_scopes.list_kauth_scopes(self.context, self.config['darwin']):
|
||||
for scope in kauth_scopes.Kauth_scopes.list_kauth_scopes(self.context, self.config['kernel']):
|
||||
|
||||
scope_name = utility.pointer_to_string(scope.ks_identifier, 128)
|
||||
|
||||
@@ -47,7 +47,7 @@ class Kauth_listeners(interfaces.plugins.PluginInterface):
|
||||
continue
|
||||
|
||||
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, callback,
|
||||
self.config['darwin'])
|
||||
self.config['kernel'])
|
||||
|
||||
yield (0, (scope_name, format_hints.Hex(listener.kll_idata), format_hints.Hex(callback), module_name,
|
||||
symbol_name))
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0
|
||||
#
|
||||
import logging
|
||||
from typing import Iterable, Callable, Tuple
|
||||
from typing import Iterable, Callable
|
||||
|
||||
from volatility3.framework import renderers, interfaces
|
||||
from volatility3.framework.configuration import requirements
|
||||
@@ -23,7 +23,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
@@ -34,9 +34,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
|
||||
context: interfaces.context.ContextInterface,
|
||||
kernel_module_name: str,
|
||||
filter_func: Callable[[int], bool] = lambda _: False) -> \
|
||||
Iterable[Tuple[interfaces.objects.ObjectInterface,
|
||||
interfaces.objects.ObjectInterface,
|
||||
interfaces.objects.ObjectInterface]]:
|
||||
Iterable[interfaces.objects.ObjectInterface]:
|
||||
"""
|
||||
Enumerates the registered kauth scopes and yields each object
|
||||
Uses smear-safe enumeration API
|
||||
@@ -50,20 +48,20 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
|
||||
yield scope
|
||||
|
||||
def _generator(self):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
for scope in self.list_kauth_scopes(self.context, self.config['darwin']):
|
||||
for scope in self.list_kauth_scopes(self.context, self.config['kernel']):
|
||||
|
||||
callback = scope.ks_callback
|
||||
if callback == 0:
|
||||
continue
|
||||
|
||||
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, callback,
|
||||
self.config['darwin'])
|
||||
self.config['kernel'])
|
||||
|
||||
identifier = utility.pointer_to_string(scope.ks_identifier, 128)
|
||||
|
||||
|
||||
@@ -48,7 +48,7 @@ class Kevents(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 2, 0)),
|
||||
@@ -148,7 +148,7 @@ class Kevents(interfaces.plugins.PluginInterface):
|
||||
filter_func = pslist.PsList.create_pid_filter(self.config.get('pid', None))
|
||||
|
||||
for task_name, pid, kn in self.list_kernel_events(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func):
|
||||
|
||||
filter_index = kn.kn_kevent.filter * -1
|
||||
|
||||
@@ -23,7 +23,7 @@ class List_Files(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'mount', plugin = mount.Mount, version = (2, 0, 0)),
|
||||
]
|
||||
@@ -165,7 +165,7 @@ class List_Files(plugins.PluginInterface):
|
||||
yield vnode, full_path
|
||||
|
||||
def _generator(self):
|
||||
for vnode, full_path in self.list_files(self.context, self.config['darwin']):
|
||||
for vnode, full_path in self.list_files(self.context, self.config['kernel']):
|
||||
|
||||
yield (0, (format_hints.Hex(vnode), full_path))
|
||||
|
||||
|
||||
@@ -22,7 +22,7 @@ class Lsmod(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
]
|
||||
|
||||
@@ -76,7 +76,7 @@ class Lsmod(plugins.PluginInterface):
|
||||
return
|
||||
|
||||
def _generator(self):
|
||||
for module in self.list_modules(self.context, self.config['darwin']):
|
||||
for module in self.list_modules(self.context, self.config['kernel']):
|
||||
|
||||
mod_name = utility.array_to_string(module.name)
|
||||
mod_size = module.size
|
||||
|
||||
@@ -21,7 +21,7 @@ class Lsof(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
|
||||
@@ -32,11 +32,12 @@ class Lsof(plugins.PluginInterface):
|
||||
]
|
||||
|
||||
def _generator(self, tasks):
|
||||
darwin = self.context.modules[self.config['kernel']]
|
||||
for task in tasks:
|
||||
pid = task.p_pid
|
||||
|
||||
for _, filepath, fd in mac.MacUtilities.files_descriptors_for_process(self.context, self.config[
|
||||
'darwin.symbol_table_name'],
|
||||
for _, filepath, fd in mac.MacUtilities.files_descriptors_for_process(self.context,
|
||||
darwin.symbol_table_name,
|
||||
task):
|
||||
if filepath and len(filepath) > 0:
|
||||
yield (0, (pid, fd, filepath))
|
||||
@@ -48,5 +49,5 @@ class Lsof(plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("File Descriptor", int), ("File Path", str)],
|
||||
self._generator(
|
||||
list_tasks(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -18,7 +18,7 @@ class Malfind(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
@@ -38,13 +38,13 @@ class Malfind(interfaces.plugins.PluginInterface):
|
||||
proc_layer = self.context.layers[proc_layer_name]
|
||||
|
||||
for vma in task.get_map_iter():
|
||||
if not vma.is_suspicious(self.context, self.context.modules[self.config['darwin']].symbol_table_name):
|
||||
if not vma.is_suspicious(self.context, self.context.modules[self.config['kernel']].symbol_table_name):
|
||||
data = proc_layer.read(vma.links.start, 64, pad = True)
|
||||
yield vma, data
|
||||
|
||||
def _generator(self, tasks):
|
||||
# determine if we're on a 32 or 64 bit kernel
|
||||
if self.context.modules[self.config['darwin']].get_type("pointer").size == 4:
|
||||
if self.context.modules[self.config['kernel']].get_type("pointer").size == 4:
|
||||
is_32bit_arch = True
|
||||
else:
|
||||
is_32bit_arch = False
|
||||
@@ -72,5 +72,5 @@ class Malfind(interfaces.plugins.PluginInterface):
|
||||
("Disasm", interfaces.renderers.Disassembly)],
|
||||
self._generator(
|
||||
list_tasks(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -21,7 +21,7 @@ class Mount(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
|
||||
]
|
||||
@@ -46,7 +46,7 @@ class Mount(plugins.PluginInterface):
|
||||
yield mount
|
||||
|
||||
def _generator(self):
|
||||
for mount in self.list_mounts(self.context, self.config['darwin']):
|
||||
for mount in self.list_mounts(self.context, self.config['kernel']):
|
||||
vfs = mount.mnt_vfsstat
|
||||
device_name = utility.array_to_string(vfs.f_mntonname)
|
||||
mount_point = utility.array_to_string(vfs.f_mntfromname)
|
||||
|
||||
@@ -24,7 +24,7 @@ class Netstat(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
|
||||
@@ -74,7 +74,7 @@ class Netstat(plugins.PluginInterface):
|
||||
continue
|
||||
|
||||
if not context.layers[task.vol.native_layer_name].is_valid(socket.vol.offset,
|
||||
socket.vol.size):
|
||||
socket.vol.size):
|
||||
continue
|
||||
|
||||
yield task_name, pid, socket
|
||||
@@ -83,7 +83,7 @@ class Netstat(plugins.PluginInterface):
|
||||
filter_func = pslist.PsList.create_pid_filter(self.config.get('pid', None))
|
||||
|
||||
for task_name, pid, socket in self.list_sockets(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func):
|
||||
|
||||
family = socket.get_family()
|
||||
|
||||
@@ -17,7 +17,7 @@ class Maps(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
@@ -32,7 +32,7 @@ class Maps(interfaces.plugins.PluginInterface):
|
||||
process_pid = task.p_pid
|
||||
|
||||
for vma in task.get_map_iter():
|
||||
path = vma.get_path(self.context, self.context.modules[self.config['darwin']].symbol_table_name)
|
||||
path = vma.get_path(self.context, self.context.modules[self.config['kernel']].symbol_table_name)
|
||||
if path == "":
|
||||
path = vma.get_special_path()
|
||||
|
||||
@@ -47,5 +47,5 @@ class Maps(interfaces.plugins.PluginInterface):
|
||||
("End", format_hints.Hex), ("Protection", str), ("Map Name", str)],
|
||||
self._generator(
|
||||
list_tasks(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -19,7 +19,7 @@ class Psaux(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)),
|
||||
requirements.ListRequirement(name = 'pid',
|
||||
@@ -96,5 +96,5 @@ class Psaux(plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Argc", int), ("Arguments", str)],
|
||||
self._generator(
|
||||
list_tasks(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -23,7 +23,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)),
|
||||
requirements.ChoiceRequirement(name = 'pslist_method',
|
||||
@@ -89,7 +89,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
list_tasks = self.get_list_tasks(self.config.get('pslist_method', self.pslist_methods[0]))
|
||||
|
||||
for task in list_tasks(self.context,
|
||||
self.config['darwin'],
|
||||
self.config['kernel'],
|
||||
filter_func = self.create_pid_filter(self.config.get('pid', None))):
|
||||
pid = task.p_pid
|
||||
ppid = task.p_ppid
|
||||
|
||||
@@ -24,7 +24,7 @@ class PsTree(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0))
|
||||
]
|
||||
@@ -48,7 +48,7 @@ class PsTree(plugins.PluginInterface):
|
||||
"""Generates the tree list of processes"""
|
||||
list_tasks = pslist.PsList.get_list_tasks(self.config.get('pslist_method', pslist.PsList.pslist_methods[0]))
|
||||
|
||||
for proc in list_tasks(self.context, self.config['darwin']):
|
||||
for proc in list_tasks(self.context, self.config['kernel']):
|
||||
self._processes[proc.p_pid] = proc
|
||||
|
||||
# Build the child/level maps
|
||||
|
||||
@@ -24,16 +24,16 @@ class Socket_filters(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
|
||||
@@ -23,16 +23,16 @@ class Timers(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 3, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin'])
|
||||
mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel'])
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
@@ -69,7 +69,7 @@ class Timers(plugins.PluginInterface):
|
||||
entry_time = -1
|
||||
|
||||
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, handler,
|
||||
self.config['darwin'])
|
||||
self.config['kernel'])
|
||||
|
||||
yield (0, (format_hints.Hex(handler), format_hints.Hex(timer.param0), format_hints.Hex(timer.param1),
|
||||
timer.deadline, entry_time, module_name, symbol_name))
|
||||
|
||||
@@ -25,14 +25,14 @@ class Trustedbsd(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 3, 0)),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0))
|
||||
]
|
||||
|
||||
def _generator(self, mods: Iterator[Any]):
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods)
|
||||
|
||||
@@ -65,7 +65,7 @@ class Trustedbsd(plugins.PluginInterface):
|
||||
continue
|
||||
|
||||
module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, call_addr,
|
||||
self.config['darwin'])
|
||||
self.config['kernel'])
|
||||
|
||||
yield (0, (check, ent_name, format_hints.Hex(call_addr), module_name, symbol_name))
|
||||
|
||||
@@ -73,4 +73,4 @@ class Trustedbsd(plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("Member", str), ("Policy Name", str), ("Handler Address", format_hints.Hex),
|
||||
("Handler Module", str), ("Handler Symbol", str)],
|
||||
self._generator(
|
||||
lsmod.Lsmod.list_modules(self.context, self.config['darwin'])))
|
||||
lsmod.Lsmod.list_modules(self.context, self.config['kernel'])))
|
||||
|
||||
@@ -20,7 +20,7 @@ class VFSevents(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS',
|
||||
requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
]
|
||||
|
||||
@@ -30,7 +30,7 @@ class VFSevents(interfaces.plugins.PluginInterface):
|
||||
Also lists which event(s) a process is registered for
|
||||
"""
|
||||
|
||||
kernel = self.context.modules[self.config['darwin']]
|
||||
kernel = self.context.modules[self.config['kernel']]
|
||||
|
||||
watcher_table = kernel.object_from_symbol("watcher_table")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user