diff --git a/volatility3/framework/plugins/windows/poolscanner.py b/volatility3/framework/plugins/windows/poolscanner.py index ce1015789..5539e1e84 100644 --- a/volatility3/framework/plugins/windows/poolscanner.py +++ b/volatility3/framework/plugins/windows/poolscanner.py @@ -222,25 +222,25 @@ class PoolScanner(plugins.PluginInterface): type_name=symbol_table + constants.BANG + "_EPROCESS", object_type="Process", size=(600, None), - skip_type_test = True, + skip_type_test=True, page_type=PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE, ), # threads on windows before windows8 PoolConstraint( - b'Thr\xe5', # -> “protected” allocation, MSB is set. - type_name = symbol_table + constants.BANG + "_ETHREAD", + b"Thr\xe5", # -> “protected” allocation, MSB is set. + type_name=symbol_table + constants.BANG + "_ETHREAD", object_type="Thread", - size = (600, None), # -> 0x0258 - size of strcut in win5.1 - skip_type_test = True, - page_type = PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE + size=(600, None), # -> 0x0258 - size of strcut in win5.1 + skip_type_test=True, + page_type=PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE, ), # threads on windows starting with windows8 PoolConstraint( - b'Thre', - type_name = symbol_table + constants.BANG + "_ETHREAD", + b"Thre", + type_name=symbol_table + constants.BANG + "_ETHREAD", object_type="Thread", - size = (600, None), # -> 0x0258 - size of strcut in win5.1 - page_type = PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE + size=(600, None), # -> 0x0258 - size of strcut in win5.1 + page_type=PoolType.PAGED | PoolType.NONPAGED | PoolType.FREE, ), # files on windows before windows 8 PoolConstraint( diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index 4ad74f61a..8790f41a7 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -499,17 +499,18 @@ class ETHREAD(objects.StructType, pool.ExecutiveObject): """Determine if the object is valid.""" try: - # validation by TID: - if self.Cid.UniqueThread % 4 != 0: # NT tids are divisible by 4 + if self.Cid.UniqueThread % 4 != 0: # NT tids are divisible by 4 return False - + # validation by PID of parent process: if self.Cid.UniqueProcess % 4 != 0: return False - + # validation by thread creation time: - if self.Cid.UniqueProcess != 4: # The System process (PID 4) has no create time + if ( + self.Cid.UniqueProcess != 4 + ): # The System process (PID 4) has no create time ctime = self.get_create_time() if not isinstance(ctime, datetime.datetime): return False @@ -518,14 +519,14 @@ class ETHREAD(objects.StructType, pool.ExecutiveObject): return False # passed all validations - return True - + return True + def get_create_time(self): return conversion.wintime_to_datetime(self.CreateTime.QuadPart) def get_exit_time(self): return conversion.wintime_to_datetime(self.ExitTime.QuadPart) - + def owning_process(self) -> interfaces.objects.ObjectInterface: """Return the EPROCESS that owns this thread."""