mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-10-01 22:14:53 +02:00
Slightly modify documentation
Include regex_scan, new functionality of volshell. Add Intermediate Symbol File (ISF) to glossary.
This commit is contained in:
+11
-4
@@ -23,7 +23,7 @@ Alignment
|
||||
.. _Array:
|
||||
|
||||
Array
|
||||
This represents a list of items, which can be access by an index, which is zero-based (meaning the first
|
||||
This represents a list of items, which can be accessed by an index, which is zero-based (meaning the first
|
||||
element has index 0). Items in arrays are almost always the same size (it is not a generic list, as in python)
|
||||
even if they are :ref:`pointers<pointer>` to different sized objects.
|
||||
|
||||
@@ -43,7 +43,14 @@ Dereference
|
||||
.. _Domain:
|
||||
|
||||
Domain
|
||||
This the grouping for input values for a mapping or mathematical function.
|
||||
The set of input values for a mapping or mathematical function.
|
||||
|
||||
I
|
||||
-
|
||||
.. _Intermediate Symbol File (ISF):
|
||||
|
||||
Intermediate Symbol File (ISF)
|
||||
They contain kernel structures and specific offsets formatted as JSON. For macOS and Linux analysis, the kernel needs to be added as an ISF file to the volatility 3 symbols directory. For Windows, the required ISF file can often be generated from PDB files automatically downloaded from Microsoft servers, and therefore does not require manual intervention.
|
||||
|
||||
M
|
||||
-
|
||||
@@ -55,7 +62,7 @@ Map, mapping
|
||||
attempts to use mathematical functional notation where possible. Within volatility a mapping is most often
|
||||
used to refer to the function for translating addresses from a higher layer (domain) to a lower layer (range).
|
||||
For further information, please see
|
||||
`Function (mathematics) in wikipedia https://en.wikipedia.org/wiki/Function_(mathematics)`
|
||||
`https://en.wikipedia.org/wiki/Function_(mathematics)`.
|
||||
|
||||
|
||||
.. _Member:
|
||||
@@ -69,7 +76,7 @@ O
|
||||
.. _Object:
|
||||
|
||||
Object
|
||||
This has a specific meaning within computer programming (as in Object Oriented Programming), but within the world
|
||||
This has a specific meaning within computer programming (as in object-oriented programming), but within the world
|
||||
of Volatility it is used to refer to a type that has been associated with a chunk of data, or a specific instance
|
||||
of a type. See also :ref:`Type<type>`.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user