mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-28 04:24:53 +02:00
Plugins: Bump remaining plugins to framework require 2.0.0
This commit is contained in:
@@ -13,6 +13,8 @@ from volatility.plugins.mac import lsmod, kauth_scopes
|
||||
class Kauth_listeners(interfaces.plugins.PluginInterface):
|
||||
""" Lists kauth listeners and their status """
|
||||
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
|
||||
@@ -16,6 +16,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
|
||||
""" Lists kauth scopes and their status """
|
||||
|
||||
_version = (1, 0, 0)
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
|
||||
@@ -14,6 +14,8 @@ from volatility.plugins.mac import pslist
|
||||
class Kevents(interfaces.plugins.PluginInterface):
|
||||
""" Lists event handlers registered by processes """
|
||||
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
event_types = {
|
||||
1: "EVFILT_READ",
|
||||
2: "EVFILT_WRITE",
|
||||
|
||||
@@ -19,6 +19,8 @@ vollog = logging.getLogger(__name__)
|
||||
class Socket_filters(plugins.PluginInterface):
|
||||
"""Enumerates kernel socket filters."""
|
||||
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
@@ -38,8 +40,8 @@ class Socket_filters(plugins.PluginInterface):
|
||||
handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, self.config['primary'], kernel, mods)
|
||||
|
||||
members_to_check = ["sf_unregistered", "sf_attach", "sf_detach", "sf_notify", "sf_getpeername",
|
||||
"sf_getsockname", \
|
||||
"sf_data_in", "sf_data_out", "sf_connect_in", "sf_connect_out", "sf_bind", "sf_setoption", \
|
||||
"sf_getsockname",
|
||||
"sf_data_in", "sf_data_out", "sf_connect_in", "sf_connect_out", "sf_bind", "sf_setoption",
|
||||
"sf_getoption", "sf_listen", "sf_ioctl"]
|
||||
|
||||
filter_list = kernel.object_from_symbol(symbol_name = "sock_filter_head")
|
||||
|
||||
@@ -10,6 +10,8 @@ from volatility.framework.objects import utility
|
||||
class VFSevents(interfaces.plugins.PluginInterface):
|
||||
""" Lists processes that are filtering file system events """
|
||||
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
event_types = [
|
||||
"CREATE_FILE", "DELETE", "STAT_CHANGED", "RENAME", "CONTENT_MODIFIED", "EXCHANGE", "FINDER_INFO_CHANGED",
|
||||
"CREATE_DIR", "CHOWN", "XATTR_MODIFIED", "XATTR_REMOVED", "DOCID_CREATED", "DOCID_CHANGED"
|
||||
|
||||
@@ -16,6 +16,7 @@ class Envars(interfaces.plugins.PluginInterface):
|
||||
"Display process environment variables"
|
||||
|
||||
_version = (1, 0, 0)
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
|
||||
@@ -31,6 +31,7 @@ class GetServiceSIDs(interfaces.plugins.PluginInterface):
|
||||
"""Lists process token sids."""
|
||||
|
||||
_version = (1, 0, 0)
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
def __init__(self, *args, **kwargs):
|
||||
super().__init__(*args, **kwargs)
|
||||
|
||||
@@ -29,6 +29,7 @@ class GetSIDs(interfaces.plugins.PluginInterface):
|
||||
"""Print the SIDs owning each process"""
|
||||
|
||||
_version = (1, 0, 0)
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
def __init__(self, *args, **kwargs):
|
||||
super().__init__(*args, **kwargs)
|
||||
|
||||
@@ -17,6 +17,7 @@ class Privs(interfaces.plugins.PluginInterface):
|
||||
"""Lists process token privileges"""
|
||||
|
||||
_version = (1, 0, 0)
|
||||
_required_framework_version = (2, 0, 0)
|
||||
|
||||
def __init__(self, *args, **kwargs):
|
||||
super().__init__(*args, **kwargs)
|
||||
|
||||
Reference in New Issue
Block a user