From c2b2321622ad1c170e10cf847b566796842a8020 Mon Sep 17 00:00:00 2001 From: atcuno Date: Sun, 19 May 2024 14:09:14 -0500 Subject: [PATCH 1/5] Add a new getcellroutine plugin that reports hooked GetCellRoutine handlers of memory mapped Windows registry hives --- .../windows/registry/getcellroutine.py | 97 +++++++++++++++++++ 1 file changed, 97 insertions(+) create mode 100644 volatility3/framework/plugins/windows/registry/getcellroutine.py diff --git a/volatility3/framework/plugins/windows/registry/getcellroutine.py b/volatility3/framework/plugins/windows/registry/getcellroutine.py new file mode 100644 index 000000000..08523d2f1 --- /dev/null +++ b/volatility3/framework/plugins/windows/registry/getcellroutine.py @@ -0,0 +1,97 @@ +# This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 +# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 +# + +import logging +from typing import List + +from volatility3.framework import constants, exceptions, interfaces, renderers +from volatility3.framework.configuration import requirements +from volatility3.framework.renderers import format_hints +from volatility3.plugins.windows import ssdt +from volatility3.plugins.windows.registry import hivelist + +vollog = logging.getLogger(__name__) + +class GetCellRoutine(interfaces.plugins.PluginInterface): + """ Reports registry hives with a hooked GetCellRoutine handler """ + + _required_framework_version = (2, 0, 0) + + @classmethod + def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: + return [ + requirements.ModuleRequirement( + name="kernel", + description="Windows kernel", + architectures=["Intel32", "Intel64"], + ), + requirements.PluginRequirement( + name="hivelist", plugin=hivelist.HiveList, version=(1, 0, 0) + ), + requirements.PluginRequirement( + name="ssdt", plugin=ssdt.SSDT, version=(1, 0, 0) + ), + ] + + def _generator(self): + kernel = self.context.modules[self.config["kernel"]] + + collection = ssdt.SSDT.build_module_collection( + self.context, kernel.layer_name, kernel.symbol_table_name + ) + + # walk each hive and validate that the GetCellRoutine handler + # is inside of the kernel (ntoskrnl) + for hive_object in hivelist.HiveList.list_hives( + context=self.context, + base_config_path=self.config_path, + layer_name=kernel.layer_name, + symbol_table=kernel.symbol_table_name + ): + hive = hive_object.hive + + try: + cellroutine = hive.GetCellRoutine + except exceptions.InvalidAddressException: + continue + + module_symbols = list( + collection.get_module_symbols_by_absolute_location(cellroutine) + ) + + if module_symbols: + for module_name, _ in module_symbols: + # GetCellRoutine handlers should only be in the kernel + if module_name not in constants.windows.KERNEL_MODULE_NAMES: + yield ( + 0, + ( + format_hints.Hex(hive.vol.offset), + hive_object.get_name() or "", + module_name, + format_hints.Hex(cellroutine) + ) + ) + # Doesn't map to any module... + else: + yield ( + 0, + ( + format_hints.Hex(hive.vol.offset), + hive_object.get_name() or "", + renderers.NotAvailableValue(), + format_hints.Hex(cellroutine) + ) + ) + + def run(self): + return renderers.TreeGrid( + [ + ("Hive Offset", renderers.format_hints.Hex), + ("Hive Name", str), + ("GetCellRoutine Module", str), + ("GetCellRoutine Handler", renderers.format_hints.Hex) + ], + self._generator(), + ) From 47eb42204e19c482ff332ce9bb36fcbe54fa49d3 Mon Sep 17 00:00:00 2001 From: atcuno Date: Sun, 19 May 2024 14:21:03 -0500 Subject: [PATCH 2/5] Fixes for black --- .../plugins/windows/registry/getcellroutine.py | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/volatility3/framework/plugins/windows/registry/getcellroutine.py b/volatility3/framework/plugins/windows/registry/getcellroutine.py index 08523d2f1..2cbb87565 100644 --- a/volatility3/framework/plugins/windows/registry/getcellroutine.py +++ b/volatility3/framework/plugins/windows/registry/getcellroutine.py @@ -14,7 +14,7 @@ from volatility3.plugins.windows.registry import hivelist vollog = logging.getLogger(__name__) class GetCellRoutine(interfaces.plugins.PluginInterface): - """ Reports registry hives with a hooked GetCellRoutine handler """ + """Reports registry hives with a hooked GetCellRoutine handler""" _required_framework_version = (2, 0, 0) @@ -32,7 +32,7 @@ class GetCellRoutine(interfaces.plugins.PluginInterface): requirements.PluginRequirement( name="ssdt", plugin=ssdt.SSDT, version=(1, 0, 0) ), - ] + ] def _generator(self): kernel = self.context.modules[self.config["kernel"]] @@ -47,7 +47,7 @@ class GetCellRoutine(interfaces.plugins.PluginInterface): context=self.context, base_config_path=self.config_path, layer_name=kernel.layer_name, - symbol_table=kernel.symbol_table_name + symbol_table=kernel.symbol_table_name, ): hive = hive_object.hive @@ -70,7 +70,7 @@ class GetCellRoutine(interfaces.plugins.PluginInterface): format_hints.Hex(hive.vol.offset), hive_object.get_name() or "", module_name, - format_hints.Hex(cellroutine) + format_hints.Hex(cellroutine), ) ) # Doesn't map to any module... @@ -81,7 +81,7 @@ class GetCellRoutine(interfaces.plugins.PluginInterface): format_hints.Hex(hive.vol.offset), hive_object.get_name() or "", renderers.NotAvailableValue(), - format_hints.Hex(cellroutine) + format_hints.Hex(cellroutine), ) ) From 4ed7d40ecb61f1d4e671f3323a1b075ad2501bfc Mon Sep 17 00:00:00 2001 From: atcuno Date: Sun, 19 May 2024 14:23:21 -0500 Subject: [PATCH 3/5] Fixes for black --- .../framework/plugins/windows/registry/getcellroutine.py | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/volatility3/framework/plugins/windows/registry/getcellroutine.py b/volatility3/framework/plugins/windows/registry/getcellroutine.py index 2cbb87565..98b3c2517 100644 --- a/volatility3/framework/plugins/windows/registry/getcellroutine.py +++ b/volatility3/framework/plugins/windows/registry/getcellroutine.py @@ -71,7 +71,7 @@ class GetCellRoutine(interfaces.plugins.PluginInterface): hive_object.get_name() or "", module_name, format_hints.Hex(cellroutine), - ) + ), ) # Doesn't map to any module... else: @@ -82,7 +82,7 @@ class GetCellRoutine(interfaces.plugins.PluginInterface): hive_object.get_name() or "", renderers.NotAvailableValue(), format_hints.Hex(cellroutine), - ) + ), ) def run(self): @@ -91,7 +91,7 @@ class GetCellRoutine(interfaces.plugins.PluginInterface): ("Hive Offset", renderers.format_hints.Hex), ("Hive Name", str), ("GetCellRoutine Module", str), - ("GetCellRoutine Handler", renderers.format_hints.Hex) + ("GetCellRoutine Handler", renderers.format_hints.Hex), ], self._generator(), ) From bc8666b64a4b722918879eda5efcadeab633bfd2 Mon Sep 17 00:00:00 2001 From: atcuno Date: Sun, 19 May 2024 14:24:53 -0500 Subject: [PATCH 4/5] Fixes for black --- volatility3/framework/plugins/windows/registry/getcellroutine.py | 1 + 1 file changed, 1 insertion(+) diff --git a/volatility3/framework/plugins/windows/registry/getcellroutine.py b/volatility3/framework/plugins/windows/registry/getcellroutine.py index 98b3c2517..ed54a135d 100644 --- a/volatility3/framework/plugins/windows/registry/getcellroutine.py +++ b/volatility3/framework/plugins/windows/registry/getcellroutine.py @@ -13,6 +13,7 @@ from volatility3.plugins.windows.registry import hivelist vollog = logging.getLogger(__name__) + class GetCellRoutine(interfaces.plugins.PluginInterface): """Reports registry hives with a hooked GetCellRoutine handler""" From 901b0fd6baeaf9779a7111172b579f13688e8ec8 Mon Sep 17 00:00:00 2001 From: atcuno Date: Sun, 19 May 2024 15:11:06 -0500 Subject: [PATCH 5/5] Fix year in header --- .../framework/plugins/windows/registry/getcellroutine.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/volatility3/framework/plugins/windows/registry/getcellroutine.py b/volatility3/framework/plugins/windows/registry/getcellroutine.py index ed54a135d..200a45a82 100644 --- a/volatility3/framework/plugins/windows/registry/getcellroutine.py +++ b/volatility3/framework/plugins/windows/registry/getcellroutine.py @@ -1,4 +1,4 @@ -# This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 +# This file is Copyright 2024 Volatility Foundation and licensed under the Volatility Software License 1.0 # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 #