diff --git a/volatility/cli/__init__.py b/volatility/cli/__init__.py index 326dfd983..f93909f13 100644 --- a/volatility/cli/__init__.py +++ b/volatility/cli/__init__.py @@ -8,6 +8,7 @@ from volatility.cli import argparse_adapter from volatility.framework import plugins, contexts from volatility.framework.configuration import depresolver from volatility.framework.configuration.depresolver import DependencyError +from volatility.framework.renderers.text import TextRenderer __author__ = 'mike' @@ -53,7 +54,7 @@ class CommandLine(object): config_path = plugin.__name__.lower() if dldr.validate_dependencies(dependencies, context = ctx, path = config_path): # Construct and run the plugin - plugin(ctx, config_path).run() + TextRenderer().render(plugin(ctx, config_path).run()) else: raise DependencyError("Unable to validate all the dependencies, please check configuration parameters") diff --git a/volatility/framework/renderers/text.py b/volatility/framework/renderers/text.py index e69de29bb..78e6f7866 100644 --- a/volatility/framework/renderers/text.py +++ b/volatility/framework/renderers/text.py @@ -0,0 +1,13 @@ +from volatility.framework import interfaces + + +class TextRenderer(interfaces.renderers.Renderer): + def __init__(self, options = None): + pass + + def get_render_options(self): + pass + + def render(self, grid): + for row in grid.populate(): + print("\t".join(row)) diff --git a/volatility/plugins/windows/pslist.py b/volatility/plugins/windows/pslist.py index 899dd6656..d08f999ad 100644 --- a/volatility/plugins/windows/pslist.py +++ b/volatility/plugins/windows/pslist.py @@ -1,5 +1,6 @@ import volatility.framework.interfaces.plugins as plugins from volatility.framework.configuration import requirements +from volatility.framework.renderers import TreeGrid class PsList(plugins.PluginInterface): @@ -32,6 +33,11 @@ class PsList(plugins.PluginInterface): # Get the process from the thread object in kernel space return ethread.owning_process() + def _generator(self, eproc): + for proc in eproc.ActiveProcessLinks: + print(proc.UniqueProcessId, proc.InheritedFromUniqueProcessId) + yield (0, (proc.UniqueProcessId, proc.InheritedFromUniqueProcessId)) + def run(self): # Use the primary twice until we figure out how to specify base layers of a particular translation layer @@ -39,5 +45,7 @@ class PsList(plugins.PluginInterface): self.config['primary'], self.config['primary'], self.config['offset']) - for proc in eproc.ActiveProcessLinks: - print(proc.UniqueProcessId) + + return TreeGrid([("PID", int), + ("PPID", int)], + self._generator(eproc))