diff --git a/volatility/framework/plugins/mac/kauth_listeners.py b/volatility/framework/plugins/mac/kauth_listeners.py index 1eed0b415..ec784f585 100644 --- a/volatility/framework/plugins/mac/kauth_listeners.py +++ b/volatility/framework/plugins/mac/kauth_listeners.py @@ -13,6 +13,8 @@ from volatility.plugins.mac import lsmod, kauth_scopes class Kauth_listeners(interfaces.plugins.PluginInterface): """ Lists kauth listeners and their status """ + _required_framework_version = (2, 0, 0) + @classmethod def get_requirements(cls): return [ diff --git a/volatility/framework/plugins/mac/kauth_scopes.py b/volatility/framework/plugins/mac/kauth_scopes.py index 1541b45c4..9a9db6909 100644 --- a/volatility/framework/plugins/mac/kauth_scopes.py +++ b/volatility/framework/plugins/mac/kauth_scopes.py @@ -16,6 +16,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface): """ Lists kauth scopes and their status """ _version = (1, 0, 0) + _required_framework_version = (2, 0, 0) @classmethod def get_requirements(cls): diff --git a/volatility/framework/plugins/mac/kevents.py b/volatility/framework/plugins/mac/kevents.py index 10154350c..b3826ccfd 100644 --- a/volatility/framework/plugins/mac/kevents.py +++ b/volatility/framework/plugins/mac/kevents.py @@ -14,6 +14,8 @@ from volatility.plugins.mac import pslist class Kevents(interfaces.plugins.PluginInterface): """ Lists event handlers registered by processes """ + _required_framework_version = (2, 0, 0) + event_types = { 1: "EVFILT_READ", 2: "EVFILT_WRITE", diff --git a/volatility/framework/plugins/mac/socket_filters.py b/volatility/framework/plugins/mac/socket_filters.py index d33e2b58a..0fde476f1 100644 --- a/volatility/framework/plugins/mac/socket_filters.py +++ b/volatility/framework/plugins/mac/socket_filters.py @@ -19,6 +19,8 @@ vollog = logging.getLogger(__name__) class Socket_filters(plugins.PluginInterface): """Enumerates kernel socket filters.""" + _required_framework_version = (2, 0, 0) + @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ @@ -38,8 +40,8 @@ class Socket_filters(plugins.PluginInterface): handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, self.config['primary'], kernel, mods) members_to_check = ["sf_unregistered", "sf_attach", "sf_detach", "sf_notify", "sf_getpeername", - "sf_getsockname", \ - "sf_data_in", "sf_data_out", "sf_connect_in", "sf_connect_out", "sf_bind", "sf_setoption", \ + "sf_getsockname", + "sf_data_in", "sf_data_out", "sf_connect_in", "sf_connect_out", "sf_bind", "sf_setoption", "sf_getoption", "sf_listen", "sf_ioctl"] filter_list = kernel.object_from_symbol(symbol_name = "sock_filter_head") diff --git a/volatility/framework/plugins/mac/vfsevents.py b/volatility/framework/plugins/mac/vfsevents.py index 2a8db4a9d..84d3adc51 100644 --- a/volatility/framework/plugins/mac/vfsevents.py +++ b/volatility/framework/plugins/mac/vfsevents.py @@ -10,6 +10,8 @@ from volatility.framework.objects import utility class VFSevents(interfaces.plugins.PluginInterface): """ Lists processes that are filtering file system events """ + _required_framework_version = (2, 0, 0) + event_types = [ "CREATE_FILE", "DELETE", "STAT_CHANGED", "RENAME", "CONTENT_MODIFIED", "EXCHANGE", "FINDER_INFO_CHANGED", "CREATE_DIR", "CHOWN", "XATTR_MODIFIED", "XATTR_REMOVED", "DOCID_CREATED", "DOCID_CHANGED" diff --git a/volatility/framework/plugins/windows/envars.py b/volatility/framework/plugins/windows/envars.py index 0653f405b..cb43351ab 100644 --- a/volatility/framework/plugins/windows/envars.py +++ b/volatility/framework/plugins/windows/envars.py @@ -16,6 +16,7 @@ class Envars(interfaces.plugins.PluginInterface): "Display process environment variables" _version = (1, 0, 0) + _required_framework_version = (2, 0, 0) @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: diff --git a/volatility/framework/plugins/windows/getservicesids.py b/volatility/framework/plugins/windows/getservicesids.py index 878cc99b8..0a5a96820 100644 --- a/volatility/framework/plugins/windows/getservicesids.py +++ b/volatility/framework/plugins/windows/getservicesids.py @@ -31,6 +31,7 @@ class GetServiceSIDs(interfaces.plugins.PluginInterface): """Lists process token sids.""" _version = (1, 0, 0) + _required_framework_version = (2, 0, 0) def __init__(self, *args, **kwargs): super().__init__(*args, **kwargs) diff --git a/volatility/framework/plugins/windows/getsids.py b/volatility/framework/plugins/windows/getsids.py index 0776eb385..7266b5787 100644 --- a/volatility/framework/plugins/windows/getsids.py +++ b/volatility/framework/plugins/windows/getsids.py @@ -29,6 +29,7 @@ class GetSIDs(interfaces.plugins.PluginInterface): """Print the SIDs owning each process""" _version = (1, 0, 0) + _required_framework_version = (2, 0, 0) def __init__(self, *args, **kwargs): super().__init__(*args, **kwargs) diff --git a/volatility/framework/plugins/windows/privileges.py b/volatility/framework/plugins/windows/privileges.py index cd642950c..35fd907d7 100644 --- a/volatility/framework/plugins/windows/privileges.py +++ b/volatility/framework/plugins/windows/privileges.py @@ -17,6 +17,7 @@ class Privs(interfaces.plugins.PluginInterface): """Lists process token privileges""" _version = (1, 0, 0) + _required_framework_version = (2, 0, 0) def __init__(self, *args, **kwargs): super().__init__(*args, **kwargs)