mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-28 20:44:52 +02:00
fix black formatting
This commit is contained in:
@@ -222,25 +222,25 @@ class PoolScanner(plugins.PluginInterface):
|
||||
type_name=symbol_table + constants.BANG + "_EPROCESS",
|
||||
object_type="Process",
|
||||
size=(600, None),
|
||||
skip_type_test = True,
|
||||
skip_type_test=True,
|
||||
page_type=PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE,
|
||||
),
|
||||
# threads on windows before windows8
|
||||
PoolConstraint(
|
||||
b'Thr\xe5', # -> “protected” allocation, MSB is set.
|
||||
type_name = symbol_table + constants.BANG + "_ETHREAD",
|
||||
b"Thr\xe5", # -> “protected” allocation, MSB is set.
|
||||
type_name=symbol_table + constants.BANG + "_ETHREAD",
|
||||
object_type="Thread",
|
||||
size = (600, None), # -> 0x0258 - size of strcut in win5.1
|
||||
skip_type_test = True,
|
||||
page_type = PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE
|
||||
size=(600, None), # -> 0x0258 - size of strcut in win5.1
|
||||
skip_type_test=True,
|
||||
page_type=PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE,
|
||||
),
|
||||
# threads on windows starting with windows8
|
||||
PoolConstraint(
|
||||
b'Thre',
|
||||
type_name = symbol_table + constants.BANG + "_ETHREAD",
|
||||
b"Thre",
|
||||
type_name=symbol_table + constants.BANG + "_ETHREAD",
|
||||
object_type="Thread",
|
||||
size = (600, None), # -> 0x0258 - size of strcut in win5.1
|
||||
page_type = PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE
|
||||
size=(600, None), # -> 0x0258 - size of strcut in win5.1
|
||||
page_type=PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE,
|
||||
),
|
||||
# files on windows before windows 8
|
||||
PoolConstraint(
|
||||
|
||||
@@ -499,17 +499,18 @@ class ETHREAD(objects.StructType, pool.ExecutiveObject):
|
||||
"""Determine if the object is valid."""
|
||||
|
||||
try:
|
||||
|
||||
# validation by TID:
|
||||
if self.Cid.UniqueThread % 4 != 0: # NT tids are divisible by 4
|
||||
if self.Cid.UniqueThread % 4 != 0: # NT tids are divisible by 4
|
||||
return False
|
||||
|
||||
|
||||
# validation by PID of parent process:
|
||||
if self.Cid.UniqueProcess % 4 != 0:
|
||||
return False
|
||||
|
||||
|
||||
# validation by thread creation time:
|
||||
if self.Cid.UniqueProcess != 4: # The System process (PID 4) has no create time
|
||||
if (
|
||||
self.Cid.UniqueProcess != 4
|
||||
): # The System process (PID 4) has no create time
|
||||
ctime = self.get_create_time()
|
||||
if not isinstance(ctime, datetime.datetime):
|
||||
return False
|
||||
@@ -518,14 +519,14 @@ class ETHREAD(objects.StructType, pool.ExecutiveObject):
|
||||
return False
|
||||
|
||||
# passed all validations
|
||||
return True
|
||||
|
||||
return True
|
||||
|
||||
def get_create_time(self):
|
||||
return conversion.wintime_to_datetime(self.CreateTime.QuadPart)
|
||||
|
||||
def get_exit_time(self):
|
||||
return conversion.wintime_to_datetime(self.ExitTime.QuadPart)
|
||||
|
||||
|
||||
def owning_process(self) -> interfaces.objects.ObjectInterface:
|
||||
"""Return the EPROCESS that owns this thread."""
|
||||
|
||||
|
||||
Reference in New Issue
Block a user