Windows Hivelist: Update dependents

This updates all plugins that depend on windows.hivelist.HiveList to use
the updated method signature, and bumps their dependency version
accordingly.

Co-authored-by: Andrew Case <andrew@dfir.org>
This commit is contained in:
David McDonald
2025-03-05 17:59:38 -06:00
co-authored by Andrew Case
parent 6092e3ee0a
commit 3a7e61b285
10 changed files with 29 additions and 55 deletions
@@ -87,7 +87,7 @@ class GetSIDs(interfaces.plugins.PluginInterface):
name="pslist", plugin=pslist.PsList, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="hivelist", plugin=hivelist.HiveList, version=(1, 0, 0)
name="hivelist", plugin=hivelist.HiveList, version=(2, 0, 0)
),
]
@@ -101,14 +101,12 @@ class GetSIDs(interfaces.plugins.PluginInterface):
key = "Microsoft\\Windows NT\\CurrentVersion\\ProfileList"
val = "ProfileImagePath"
kernel = self.context.modules[self.config["kernel"]]
sids = {}
for hive in hivelist.HiveList.list_hives(
context=self.context,
base_config_path=self.config_path,
layer_name=kernel.layer_name,
symbol_table=kernel.symbol_table_name,
self.context,
self.config_path,
self.config["kernel"],
filter_string="config\\software",
hive_offsets=None,
):