Yapf-0.28.0 rerun across the whole codebase.

This commit is contained in:
Mike Auty
2019-09-21 21:08:23 +01:00
parent dad88692b8
commit 72567e1c50
91 changed files with 1208 additions and 1124 deletions
+7 -4
View File
@@ -20,10 +20,13 @@ class ConfigWriter(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.BooleanRequirement(
name = 'extra', description = 'Outputs whole configuration tree', default = False, optional = True)
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.BooleanRequirement(name = 'extra',
description = 'Outputs whole configuration tree',
default = False,
optional = True)
]
def _generator(self):
+15 -14
View File
@@ -23,20 +23,21 @@ class LayerWriter(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.StringRequirement(
name = 'layer_name', description = 'Name of the layer to write out', default = None, optional = True),
requirements.StringRequirement(
name = 'output',
description = 'Filename to output the chosen layer',
optional = True,
default = cls.default_output_name),
requirements.IntRequirement(
name = 'block_size',
description = "Size of blocks to copy over",
default = cls.default_block_size,
optional = True)
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.StringRequirement(name = 'layer_name',
description = 'Name of the layer to write out',
default = None,
optional = True),
requirements.StringRequirement(name = 'output',
description = 'Filename to output the chosen layer',
optional = True,
default = cls.default_output_name),
requirements.IntRequirement(name = 'block_size',
description = "Size of blocks to copy over",
default = cls.default_block_size,
optional = True)
]
def _generator(self):
+20 -21
View File
@@ -24,8 +24,9 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
]
@@ -58,22 +59,19 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
bang_addrs = []
# find '#' values on the heap
for address in proc_layer.scan(
self.context,
scanners.BytesScanner(b"#"),
sections = task.get_process_memory_sections(heap_only = True)):
for address in proc_layer.scan(self.context,
scanners.BytesScanner(b"#"),
sections = task.get_process_memory_sections(heap_only = True)):
bang_addrs.append(struct.pack(pack_format, address))
history_entries = []
for address, _ in proc_layer.scan(
self.context,
scanners.MultiStringScanner(bang_addrs),
sections = task.get_process_memory_sections(heap_only = True)):
hist = self.context.object(
bash_table_name + constants.BANG + "hist_entry",
offset = address - ts_offset,
layer_name = proc_layer_name)
for address, _ in proc_layer.scan(self.context,
scanners.MultiStringScanner(bang_addrs),
sections = task.get_process_memory_sections(heap_only = True)):
hist = self.context.object(bash_table_name + constants.BANG + "hist_entry",
offset = address - ts_offset,
layer_name = proc_layer_name)
if hist.is_valid():
history_entries.append(hist)
@@ -87,18 +85,19 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("CommandTime", datetime.datetime),
("Command", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
def generate_timeline(self):
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
for row in self._generator(
pslist.PsList.list_tasks(
self.context, self.config['primary'], self.config['vmlinux'], filter_func = filter_func)):
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)):
_depth, row_data = row
description = "{} ({}): \"{}\"".format(row_data[0], row_data[1], row_data[3])
yield (description, timeliner.TimeLinerType.CREATED, row_data[2])
@@ -22,8 +22,9 @@ class Check_afinfo(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
]
@@ -63,8 +64,11 @@ class Check_afinfo(plugins.PluginInterface):
def _generator(self):
linux.LinuxUtilities.aslr_mask_symbol_table(self.context, self.config['vmlinux'], self.config['primary'])
vmlinux = contexts.Module(
self.context, self.config['vmlinux'], self.config['primary'], 0, absolute_symbol_addresses = True)
vmlinux = contexts.Module(self.context,
self.config['vmlinux'],
self.config['primary'],
0,
absolute_symbol_addresses = True)
op_members = vmlinux.get_type('file_operations').members
seq_members = vmlinux.get_type('seq_operations').members
@@ -29,8 +29,9 @@ class Check_syscall(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
]
@@ -123,8 +124,11 @@ class Check_syscall(plugins.PluginInterface):
def _generator(self):
linux.LinuxUtilities.aslr_mask_symbol_table(self.context, self.config['vmlinux'], self.config['primary'])
vmlinux = contexts.Module(
self.context, self.config['vmlinux'], self.config['primary'], 0, absolute_symbol_addresses = True)
vmlinux = contexts.Module(self.context,
self.config['vmlinux'],
self.config['primary'],
0,
absolute_symbol_addresses = True)
ptr_sz = vmlinux.get_type("pointer").size
if ptr_sz == 4:
@@ -153,8 +157,10 @@ class Check_syscall(plugins.PluginInterface):
tables.append(("32bit", ia32_info))
for (table_name, (tableaddr, tblsz)) in tables:
table = vmlinux.object(
object_type = "array", subtype = vmlinux.get_type("pointer"), offset = tableaddr, count = tblsz)
table = vmlinux.object(object_type = "array",
subtype = vmlinux.get_type("pointer"),
offset = tableaddr,
count = tblsz)
for (i, call_addr) in enumerate(table):
if not call_addr:
+7 -7
View File
@@ -20,8 +20,9 @@ class Elfs(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -51,8 +52,7 @@ class Elfs(plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Start", format_hints.Hex),
("End", format_hints.Hex), ("File Path", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
+3 -2
View File
@@ -21,8 +21,9 @@ class Lsmod(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
]
+7 -7
View File
@@ -22,8 +22,9 @@ class Lsof(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -44,8 +45,7 @@ class Lsof(plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("FD", int), ("Path", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
@@ -20,8 +20,9 @@ class Malfind(interfaces_plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
]
@@ -68,8 +69,7 @@ class Malfind(interfaces_plugins.PluginInterface):
("End", format_hints.Hex), ("Protection", str), ("Hexdump", format_hints.HexBytes),
("Disasm", interfaces_renderers.Disassembly)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
+7 -7
View File
@@ -19,8 +19,9 @@ class Maps(plugins.PluginInterface):
def get_requirements(cls):
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -60,8 +61,7 @@ class Maps(plugins.PluginInterface):
("PgOff", format_hints.Hex), ("Major", int), ("Minor", int), ("Inode", int),
("File Path", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = filter_func)))
+7 -7
View File
@@ -19,8 +19,9 @@ class PsList(interfaces_plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
]
@@ -47,11 +48,10 @@ class PsList(interfaces_plugins.PluginInterface):
return lambda _: False
def _generator(self):
for task in self.list_tasks(
self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
for task in self.list_tasks(self.context,
self.config['primary'],
self.config['vmlinux'],
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
pid = task.pid
ppid = 0
if task.parent:
+24 -23
View File
@@ -24,8 +24,9 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -58,24 +59,23 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
bang_addrs = []
# find '#' values on the heap
for address in proc_layer.scan(
self.context,
scanners.BytesScanner(b"#"),
sections = task.get_process_memory_sections(self.context, self.config['darwin'],
rw_no_file = True)):
for address in proc_layer.scan(self.context,
scanners.BytesScanner(b"#"),
sections = task.get_process_memory_sections(self.context,
self.config['darwin'],
rw_no_file = True)):
bang_addrs.append(struct.pack(pack_format, address))
history_entries = []
for address, _ in proc_layer.scan(
self.context,
scanners.MultiStringScanner(bang_addrs),
sections = task.get_process_memory_sections(self.context, self.config['darwin'],
rw_no_file = True)):
hist = self.context.object(
bash_table_name + constants.BANG + "hist_entry",
offset = address - ts_offset,
layer_name = proc_layer_name)
for address, _ in proc_layer.scan(self.context,
scanners.MultiStringScanner(bang_addrs),
sections = task.get_process_memory_sections(self.context,
self.config['darwin'],
rw_no_file = True)):
hist = self.context.object(bash_table_name + constants.BANG + "hist_entry",
offset = address - ts_offset,
layer_name = proc_layer_name)
if hist.is_valid():
history_entries.append(hist)
@@ -89,18 +89,19 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("CommandTime", datetime.datetime),
("Command", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
def generate_timeline(self):
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
for row in self._generator(
pslist.PsList.list_tasks(
self.context, self.config['primary'], self.config['darwin'], filter_func = filter_func)):
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)):
_depth, row_data = row
description = "{} ({}): \"{}\"".format(row_data[0], row_data[1], row_data[3])
yield (description, timeliner.TimeLinerType.CREATED, row_data[2])
@@ -20,8 +20,9 @@ class Check_syscall(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
]
@@ -22,8 +22,9 @@ class Check_sysctl(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
]
@@ -21,8 +21,9 @@ class Check_trap_table(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
]
+3 -2
View File
@@ -19,8 +19,9 @@ class Lsmod(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Linux kernel symbols")
]
+7 -7
View File
@@ -19,8 +19,9 @@ class lsof(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Kernel Address Space', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Kernel Address Space',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac Kernel"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -38,8 +39,7 @@ class lsof(plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("File Descriptor", int), ("File Path", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
+7 -7
View File
@@ -18,8 +18,9 @@ class Malfind(interfaces_plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Linux kernel symbols")
]
@@ -66,8 +67,7 @@ class Malfind(interfaces_plugins.PluginInterface):
("End", format_hints.Hex), ("Protection", str), ("Hexdump", format_hints.HexBytes),
("Disasm", interfaces_renderers.Disassembly)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
+7 -7
View File
@@ -21,8 +21,9 @@ class Netstat(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Kernel Address Space', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Kernel Address Space',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac Kernel"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -78,8 +79,7 @@ class Netstat(plugins.PluginInterface):
return renderers.TreeGrid([("Offset", format_hints.Hex), ("Proto", str), ("Local IP", str), ("Local Port", int),
("Remote IP", str), ("Remote Port", int), ("State", str), ("Process", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
@@ -17,8 +17,9 @@ class Maps(interfaces_plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Linux kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -42,8 +43,7 @@ class Maps(interfaces_plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Start", format_hints.Hex),
("End", format_hints.Hex), ("Protection", str), ("Map Name", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
+7 -7
View File
@@ -17,8 +17,9 @@ class Psaux(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -89,8 +90,7 @@ class Psaux(plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Argc", int), ("Arguments", str)],
self._generator(
pslist.PsList.list_tasks(
self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
pslist.PsList.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
+7 -7
View File
@@ -21,8 +21,9 @@ class PsList(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
]
@@ -42,11 +43,10 @@ class PsList(interfaces.plugins.PluginInterface):
return filter_func
def _generator(self):
for task in self.list_tasks(
self.context,
self.config['primary'],
self.config['darwin'],
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
for task in self.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
pid = task.p_pid
ppid = task.p_ppid
name = utility.array_to_string(task.p_comm)
+3 -2
View File
@@ -22,8 +22,9 @@ class PsTree(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
]
@@ -23,8 +23,9 @@ class Check_syscall(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (1, 0, 0))
]
@@ -36,11 +37,10 @@ class Check_syscall(plugins.PluginInterface):
policy_list = kernel.object_from_symbol(symbol_name = "_mac_policy_list").cast("mac_policy_list")
entries = kernel.object(
object_type = "array",
offset = policy_list.entries.dereference().vol.offset,
subtype = kernel.get_type('mac_policy_list_element'),
count = policy_list.staticmax + 1)
entries = kernel.object(object_type = "array",
offset = policy_list.entries.dereference().vol.offset,
subtype = kernel.get_type('mac_policy_list_element'),
count = policy_list.staticmax + 1)
mask = self.context.layers[self.config['primary']].address_mask
mods_list = [(mod.name, mod.address & mask, (mod.address & mask) + mod.size) for mod in mods]
+8 -10
View File
@@ -72,11 +72,10 @@ class Timeliner(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.StringRequirement(
name = 'plugins',
description = "Comma separated list of plugins to run",
optional = True,
default = None),
requirements.StringRequirement(name = 'plugins',
description = "Comma separated list of plugins to run",
optional = True,
default = None),
requirements.BooleanRequirement(
name = 'record-config',
description = "Whether to record the state of all the plugins once complete",
@@ -150,11 +149,10 @@ class Timeliner(interfaces.plugins.PluginInterface):
json.dump(total_config, fp, sort_keys = True, indent = 2)
self.produce_file(filedata)
return renderers.TreeGrid(
columns = [("Plugin", str), ("Description", str), ("Created Date", datetime.datetime),
("Modified Date", datetime.datetime), ("Accessed Date", datetime.datetime),
("Changed Date", datetime.datetime)],
generator = self._generator(runable_plugins))
return renderers.TreeGrid(columns = [("Plugin", str), ("Description", str), ("Created Date", datetime.datetime),
("Modified Date", datetime.datetime), ("Accessed Date", datetime.datetime),
("Changed Date", datetime.datetime)],
generator = self._generator(runable_plugins))
def build_configuration(self):
"""Builds the configuration to save for the plugin such that it can be
@@ -24,8 +24,9 @@ class Callbacks(interfaces_plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.PluginRequirement(name = 'ssdt', plugin = ssdt.SSDT, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'svcscan', plugin = svcscan.SvcScan, version = (1, 0, 0))
@@ -52,13 +53,12 @@ class Callbacks(interfaces_plugins.PluginInterface):
else:
symbol_filename = "callbacks-x86"
return intermed.IntermediateSymbolTable.create(
context,
config_path,
"windows",
symbol_filename,
native_types = native_types,
table_mapping = table_mapping)
return intermed.IntermediateSymbolTable.create(context,
config_path,
"windows",
symbol_filename,
native_types = native_types,
table_mapping = table_mapping)
@classmethod
def list_notify_routines(cls, context: interfaces.context.ContextInterface, layer_name: str, symbol_table: str,
@@ -97,11 +97,10 @@ class Callbacks(interfaces_plugins.PluginInterface):
else:
count = 8
fast_refs = ntkrnlmp.object(
object_type = "array",
offset = symbol_offset,
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
count = count)
fast_refs = ntkrnlmp.object(object_type = "array",
offset = symbol_offset,
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
count = count)
for fast_ref in fast_refs:
try:
@@ -143,11 +142,10 @@ class Callbacks(interfaces_plugins.PluginInterface):
if callback_count == 0:
return
fast_refs = ntkrnlmp.object(
object_type = "array",
offset = symbol_offset,
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
count = callback_count)
fast_refs = ntkrnlmp.object(object_type = "array",
offset = symbol_offset,
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
count = callback_count)
for fast_ref in fast_refs:
try:
@@ -183,8 +181,9 @@ class Callbacks(interfaces_plugins.PluginInterface):
return
full_type_name = callback_table_name + constants.BANG + "_KBUGCHECK_REASON_CALLBACK_RECORD"
callback_record = context.object(
object_type = full_type_name, offset = kvo + list_offset, layer_name = layer_name)
callback_record = context.object(object_type = full_type_name,
offset = kvo + list_offset,
layer_name = layer_name)
for callback in callback_record.Entry:
@@ -233,12 +232,11 @@ class Callbacks(interfaces_plugins.PluginInterface):
continue
try:
component = context.object(
symbol_table + constants.BANG + "string",
layer_name = layer_name,
offset = callback.Component,
max_length = 64,
errors = "replace")
component = context.object(symbol_table + constants.BANG + "string",
layer_name = layer_name,
offset = callback.Component,
max_length = 64,
errors = "replace")
except exceptions.InvalidAddressException:
component = renderers.UnreadableValue()
+13 -13
View File
@@ -18,12 +18,14 @@ class CmdLine(interfaces_plugins.PluginInterface):
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
requirements.IntRequirement(
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
requirements.IntRequirement(name = 'pid',
description = "Process ID to include (all other processes are excluded)",
optional = True)
]
def _generator(self, procs):
@@ -34,10 +36,9 @@ class CmdLine(interfaces_plugins.PluginInterface):
proc_layer_name = proc.add_process_layer()
try:
peb = self._context.object(
self.config["nt_symbols"] + constants.BANG + "_PEB",
layer_name = proc_layer_name,
offset = proc.Peb)
peb = self._context.object(self.config["nt_symbols"] + constants.BANG + "_PEB",
layer_name = proc_layer_name,
offset = proc.Peb)
result_text = peb.ProcessParameters.CommandLine.get_string()
@@ -54,8 +55,7 @@ class CmdLine(interfaces_plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Args", str)],
self._generator(
pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
+12 -11
View File
@@ -43,8 +43,11 @@ class DllDump(interfaces_plugins.PluginInterface):
]
def _generator(self, procs):
pe_table_name = intermed.IntermediateSymbolTable.create(
self.context, self.config_path, "windows", "pe", class_types = extensions.pe.class_types)
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
self.config_path,
"windows",
"pe",
class_types = extensions.pe.class_types)
filter_func = lambda _: False
if self.config.get('address', None) is not None:
@@ -80,10 +83,9 @@ class DllDump(interfaces_plugins.PluginInterface):
filedata = interfaces_plugins.FileInterface("pid.{0}.{1}.{2:#x}.dmp".format(
proc.UniqueProcessId, ntpath.basename(vad.get_file_name()), vad.get_start()))
dos_header = self.context.object(
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = vad.get_start(),
layer_name = proc_layer_name)
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = vad.get_start(),
layer_name = proc_layer_name)
for offset, data in dos_header.reconstruct():
filedata.data.seek(offset)
@@ -101,8 +103,7 @@ class DllDump(interfaces_plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Result", str)],
self._generator(
pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
+14 -13
View File
@@ -18,12 +18,14 @@ class DllList(interfaces_plugins.PluginInterface):
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
requirements.IntRequirement(
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
requirements.IntRequirement(name = 'pid',
description = "Process ID to include (all other processes are excluded)",
optional = True)
]
def _generator(self, procs):
@@ -41,10 +43,10 @@ class DllList(interfaces_plugins.PluginInterface):
pass
yield (0, (proc.UniqueProcessId,
proc.ImageFileName.cast(
"string", max_length = proc.ImageFileName.vol.count, errors = 'replace'),
format_hints.Hex(entry.DllBase), format_hints.Hex(entry.SizeOfImage), BaseDllName,
FullDllName))
proc.ImageFileName.cast("string",
max_length = proc.ImageFileName.vol.count,
errors = 'replace'), format_hints.Hex(entry.DllBase),
format_hints.Hex(entry.SizeOfImage), BaseDllName, FullDllName))
def run(self):
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
@@ -52,8 +54,7 @@ class DllList(interfaces_plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Base", format_hints.Hex),
("Size", format_hints.Hex), ("Name", str), ("Path", str)],
self._generator(
pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
@@ -28,8 +28,9 @@ class DriverIrp(plugins.PluginInterface):
return [
requirements.PluginRequirement(name = 'ssdt', plugin = ssdt.SSDT, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'driverscan', plugin = driverscan.DriverScan, version = (1, 0, 0)),
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -20,8 +20,9 @@ class DriverScan(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -18,8 +18,9 @@ class FileScan(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
+30 -21
View File
@@ -37,11 +37,13 @@ class Handles(interfaces_plugins.PluginInterface):
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.IntRequirement(
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
requirements.IntRequirement(name = 'pid',
description = "Process ID to include (all other processes are excluded)",
optional = True)
]
def _decode_pointer(self, value, magic):
@@ -86,8 +88,9 @@ class Handles(interfaces_plugins.PluginInterface):
offset = self._decode_pointer(handle_table_entry.LowValue, magic)
# print("LowValue: {0:#x} Magic: {1:#x} Offset: {2:#x}".format(handle_table_entry.InfoTable, magic, offset))
object_header = self.context.object(
self.config["nt_symbols"] + constants.BANG + "_OBJECT_HEADER", virtual, offset = offset)
object_header = self.context.object(self.config["nt_symbols"] + constants.BANG + "_OBJECT_HEADER",
virtual,
offset = offset)
object_header.GrantedAccess = handle_table_entry.GrantedAccessBits
object_header.HandleValue = handle_value
@@ -163,8 +166,10 @@ class Handles(interfaces_plugins.PluginInterface):
except exceptions.SymbolError:
table_addr = ntkrnlmp.get_symbol("ObpObjectTypes").address
ptrs = ntkrnlmp.object(
object_type = "array", offset = table_addr, subtype = ntkrnlmp.get_type("pointer"), count = 100)
ptrs = ntkrnlmp.object(object_type = "array",
offset = table_addr,
subtype = ntkrnlmp.get_type("pointer"),
count = 100)
for i, ptr in enumerate(ptrs): # type: ignore
# the first entry in the table is always null. break the
@@ -216,8 +221,11 @@ class Handles(interfaces_plugins.PluginInterface):
if not self.context.layers[virtual].is_valid(offset):
return
table = ntkrnlmp.object(
object_type = "array", offset = offset, subtype = subtype, count = int(count), absolute = True)
table = ntkrnlmp.object(object_type = "array",
offset = offset,
subtype = subtype,
count = int(count),
absolute = True)
layer_object = self.context.layers[virtual]
masked_offset = (offset & layer_object.maximum_address)
@@ -232,8 +240,8 @@ class Handles(interfaces_plugins.PluginInterface):
handle_multiplier = 4
handle_level_base = depth * count * handle_multiplier
handle_value = (
(entry.vol.offset - masked_offset) / (subtype.size / handle_multiplier)) + handle_level_base
handle_value = ((entry.vol.offset - masked_offset) /
(subtype.size / handle_multiplier)) + handle_level_base
item = self._get_item(entry, handle_value)
@@ -263,10 +271,12 @@ class Handles(interfaces_plugins.PluginInterface):
def _generator(self, procs):
type_map = self.get_type_map(
context = self.context, layer_name = self.config["primary"], symbol_table = self.config["nt_symbols"])
cookie = self.find_cookie(
context = self.context, layer_name = self.config["primary"], symbol_table = self.config["nt_symbols"])
type_map = self.get_type_map(context = self.context,
layer_name = self.config["primary"],
symbol_table = self.config["nt_symbols"])
cookie = self.find_cookie(context = self.context,
layer_name = self.config["primary"],
symbol_table = self.config["nt_symbols"])
for proc in procs:
@@ -321,8 +331,7 @@ class Handles(interfaces_plugins.PluginInterface):
("HandleValue", format_hints.Hex), ("Type", str),
("GrantedAccess", format_hints.Hex), ("Name", str)],
self._generator(
pslist.PsList.list_processes(
self.context,
self.config['primary'],
self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(self.context,
self.config['primary'],
self.config['nt_symbols'],
filter_func = filter_func)))
+30 -23
View File
@@ -20,8 +20,9 @@ class Info(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
]
@@ -57,16 +58,18 @@ class Info(plugins.PluginInterface):
native_types = self.context.symbol_space[self.config["nt_symbols"]].natives
kdbg_table_name = intermed.IntermediateSymbolTable.create(
self.context,
self.config_path,
"windows",
"kdbg",
native_types = native_types,
class_types = extensions.kdbg.class_types)
kdbg_table_name = intermed.IntermediateSymbolTable.create(self.context,
self.config_path,
"windows",
"kdbg",
native_types = native_types,
class_types = extensions.kdbg.class_types)
pe_table_name = intermed.IntermediateSymbolTable.create(
self.context, self.config_path, "windows", "pe", class_types = extensions.pe.class_types)
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
self.config_path,
"windows",
"pe",
class_types = extensions.pe.class_types)
kvo = virtual_layer.config["kernel_virtual_offset"]
@@ -74,10 +77,9 @@ class Info(plugins.PluginInterface):
kdbg_offset = ntkrnlmp.get_symbol("KdDebuggerDataBlock").address
kdbg = self.context.object(
kdbg_table_name + constants.BANG + "_KDDEBUGGER_DATA64",
offset = kvo + kdbg_offset,
layer_name = virtual_layer_name)
kdbg = self.context.object(kdbg_table_name + constants.BANG + "_KDDEBUGGER_DATA64",
offset = kvo + kdbg_offset,
layer_name = virtual_layer_name)
yield (0, ("Kernel Base", hex(self.config["primary.kernel_virtual_offset"])))
yield (0, ("DTB", hex(self.config["primary.page_map_offset"])))
@@ -94,8 +96,9 @@ class Info(plugins.PluginInterface):
vers_offset = ntkrnlmp.get_symbol("KdVersionBlock").address
vers = ntkrnlmp.object(
object_type = "_DBGKD_GET_VERSION64", layer_name = virtual_layer_name, offset = vers_offset)
vers = ntkrnlmp.object(object_type = "_DBGKD_GET_VERSION64",
layer_name = virtual_layer_name,
offset = vers_offset)
yield (0, ("KdVersionBlock", hex(vers.vol.offset)))
yield (0, ("Major/Minor", "{0}.{1}".format(vers.MajorVersion, vers.MinorVersion)))
@@ -103,8 +106,9 @@ class Info(plugins.PluginInterface):
cpu_count_offset = ntkrnlmp.get_symbol("KeNumberProcessors").address
cpu_count = ntkrnlmp.object(
object_type = "unsigned int", layer_name = virtual_layer_name, offset = cpu_count_offset)
cpu_count = ntkrnlmp.object(object_type = "unsigned int",
layer_name = virtual_layer_name,
offset = cpu_count_offset)
yield (0, ("KeNumberProcessors", str(cpu_count)))
@@ -114,8 +118,10 @@ class Info(plugins.PluginInterface):
else:
kuser_addr = 0xFFFFF78000000000
kuser = ntkrnlmp.object(
object_type = "_KUSER_SHARED_DATA", layer_name = virtual_layer_name, offset = kuser_addr, absolute = True)
kuser = ntkrnlmp.object(object_type = "_KUSER_SHARED_DATA",
layer_name = virtual_layer_name,
offset = kuser_addr,
absolute = True)
yield (0, ("SystemTime", str(kuser.SystemTime.get_time())))
yield (0, ("NtSystemRoot",
@@ -126,8 +132,9 @@ class Info(plugins.PluginInterface):
# yield (0, ("KdDebuggerEnabled", "True" if kuser.KdDebuggerEnabled else "False"))
# yield (0, ("SafeBootMode", "True" if kuser.SafeBootMode else "False"))
dos_header = self.context.object(
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER", offset = kvo, layer_name = virtual_layer_name)
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = kvo,
layer_name = virtual_layer_name)
nt_header = dos_header.get_nt_header()
@@ -20,11 +20,13 @@ class Malfind(interfaces.plugins.PluginInterface):
def get_requirements(cls):
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.IntRequirement(
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
requirements.IntRequirement(name = 'pid',
description = "Process ID to include (all other processes are excluded)",
optional = True)
]
@classmethod
@@ -125,8 +127,7 @@ class Malfind(interfaces.plugins.PluginInterface):
("CommitCharge", int), ("PrivateMemory", int), ("Hexdump", format_hints.HexBytes),
("Disasm", interfaces.renderers.Disassembly)],
self._generator(
pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
+21 -16
View File
@@ -26,8 +26,9 @@ class ModDump(interfaces.plugins.PluginInterface):
return [
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'modules', plugin = modules.Modules, version = (1, 0, 0)),
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
]
@@ -53,15 +54,18 @@ class ModDump(interfaces.plugins.PluginInterface):
seen_ids = [] # type: List[interfaces.objects.ObjectInterface]
filter_func = pslist.PsList.create_pid_filter(pids or [])
for proc in pslist.PsList.list_processes(
context = context, layer_name = layer_name, symbol_table = symbol_table, filter_func = filter_func):
for proc in pslist.PsList.list_processes(context = context,
layer_name = layer_name,
symbol_table = symbol_table,
filter_func = filter_func):
proc_layer_name = proc.add_process_layer()
try:
# create the session space object in the process' own layer.
# not all processes have a valid session pointer.
session_space = context.object(
symbol_table + constants.BANG + "_MM_SESSION_SPACE", layer_name = layer_name, offset = proc.Session)
session_space = context.object(symbol_table + constants.BANG + "_MM_SESSION_SPACE",
layer_name = layer_name,
offset = proc.Session)
if session_space.SessionId in seen_ids:
continue
@@ -101,8 +105,11 @@ class ModDump(interfaces.plugins.PluginInterface):
def _generator(self, mods):
session_layers = list(self.get_session_layers(self.context, self.config['primary'], self.config['nt_symbols']))
pe_table_name = intermed.IntermediateSymbolTable.create(
self.context, self.config_path, "windows", "pe", class_types = pe.class_types)
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
self.config_path,
"windows",
"pe",
class_types = pe.class_types)
for mod in mods:
try:
@@ -115,10 +122,9 @@ class ModDump(interfaces.plugins.PluginInterface):
result_text = "Cannot find a viable session layer for {0:#x}".format(mod.DllBase)
else:
try:
dos_header = self.context.object(
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = mod.DllBase,
layer_name = session_layer_name)
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = mod.DllBase,
layer_name = session_layer_name)
filedata = interfaces.plugins.FileInterface("module.{0:#x}.dmp".format(mod.DllBase))
@@ -143,7 +149,6 @@ class ModDump(interfaces.plugins.PluginInterface):
def run(self):
return renderers.TreeGrid([("Base", format_hints.Hex), ("Name", str), ("Result", str)],
self._generator(
modules.Modules.list_modules(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'])))
modules.Modules.list_modules(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'])))
@@ -18,8 +18,9 @@ class ModScan(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -19,8 +19,9 @@ class Modules(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
]
@@ -18,8 +18,9 @@ class MutantScan(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -27,17 +27,22 @@ class ProcDump(interfaces_plugins.PluginInterface):
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.IntRequirement(
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
requirements.IntRequirement(name = 'pid',
description = "Process ID to include (all other processes are excluded)",
optional = True)
]
def _generator(self, procs):
pe_table_name = intermed.IntermediateSymbolTable.create(
self.context, self.config_path, "windows", "pe", class_types = pe.class_types)
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
self.config_path,
"windows",
"pe",
class_types = pe.class_types)
for proc in procs:
process_name = utility.array_to_string(proc.ImageFileName)
@@ -45,15 +50,13 @@ class ProcDump(interfaces_plugins.PluginInterface):
proc_layer_name = proc.add_process_layer()
try:
peb = self._context.object(
self.config["nt_symbols"] + constants.BANG + "_PEB",
layer_name = proc_layer_name,
offset = proc.Peb)
peb = self._context.object(self.config["nt_symbols"] + constants.BANG + "_PEB",
layer_name = proc_layer_name,
offset = proc.Peb)
dos_header = self.context.object(
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = peb.ImageBaseAddress,
layer_name = proc_layer_name)
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = peb.ImageBaseAddress,
layer_name = proc_layer_name)
filedata = interfaces_plugins.FileInterface("pid.{0}.{1:#x}.dmp".format(
proc.UniqueProcessId, peb.ImageBaseAddress))
@@ -81,8 +84,7 @@ class ProcDump(interfaces_plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Result", str)],
self._generator(
pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
+14 -14
View File
@@ -22,17 +22,18 @@ class PsList(plugins.PluginInterface, timeliner.TimeLinerInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
# TODO: Convert this to a ListRequirement so that people can filter on sets of pids
requirements.BooleanRequirement(
name = 'physical',
description = 'Display physical offsets instead of virtual',
default = cls.PHYSICAL_DEFAULT,
optional = True),
requirements.IntRequirement(
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
requirements.BooleanRequirement(name = 'physical',
description = 'Display physical offsets instead of virtual',
default = cls.PHYSICAL_DEFAULT,
optional = True),
requirements.IntRequirement(name = 'pid',
description = "Process ID to include (all other processes are excluded)",
optional = True)
]
@classmethod
@@ -124,11 +125,10 @@ class PsList(plugins.PluginInterface, timeliner.TimeLinerInterface):
if not isinstance(memory, layers.intel.Intel):
raise TypeError("Primary layer is not an intel layer")
for proc in self.list_processes(
self.context,
self.config['primary'],
self.config['nt_symbols'],
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
for proc in self.list_processes(self.context,
self.config['primary'],
self.config['nt_symbols'],
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
if not self.config.get('physical', self.PHYSICAL_DEFAULT):
offset = proc.vol.offset
@@ -19,8 +19,9 @@ class PsScan(plugins.PluginInterface, timeliner.TimeLinerInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -21,19 +21,21 @@ class HiveList(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.StringRequirement(
name = 'filter', description = "String to filter hive names returned", optional = True, default = None)
requirements.StringRequirement(name = 'filter',
description = "String to filter hive names returned",
optional = True,
default = None)
]
def _generator(self) -> Iterator[Tuple[int, Tuple[int, str]]]:
for hive in self.list_hive_objects(
context = self.context,
layer_name = self.config["primary"],
symbol_table = self.config["nt_symbols"],
filter_string = self.config.get('filter', None)):
for hive in self.list_hive_objects(context = self.context,
layer_name = self.config["primary"],
symbol_table = self.config["nt_symbols"],
filter_string = self.config.get('filter', None)):
yield (0, (format_hints.Hex(hive.vol.offset), hive.get_name() or ""))
@@ -69,12 +71,11 @@ class HiveList(plugins.PluginInterface):
for hive_offset in hive_offsets:
# Construct the hive
reg_config_path = cls.make_subconfig(
context = context,
base_config_path = base_config_path,
hive_offset = hive_offset,
base_layer = layer_name,
nt_symbols = symbol_table)
reg_config_path = cls.make_subconfig(context = context,
base_config_path = base_config_path,
hive_offset = hive_offset,
base_layer = layer_name,
nt_symbols = symbol_table)
try:
hive = registry.RegistryHive(context, reg_config_path, name = 'hive' + hex(hive_offset))
@@ -19,8 +19,9 @@ class HiveScan(plugins.PluginInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -24,15 +24,20 @@ class PrintKey(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.PluginRequirement(name = 'hivelist', plugin = hivelist.HiveList, version = (1, 0, 0)),
requirements.IntRequirement(name = 'offset', description = "Hive Offset", default = None, optional = True),
requirements.StringRequirement(
name = 'key', description = "Key to start from", default = None, optional = True),
requirements.BooleanRequirement(
name = 'recurse', description = 'Recurses through keys', default = False, optional = True)
requirements.StringRequirement(name = 'key',
description = "Key to start from",
default = None,
optional = True),
requirements.BooleanRequirement(name = 'recurse',
description = 'Recurses through keys',
default = False,
optional = True)
]
@classmethod
@@ -134,12 +139,11 @@ class PrintKey(interfaces.plugins.PluginInterface):
key: str = None,
recurse: bool = False):
for hive in hivelist.HiveList.list_hives(
self.context,
self.config_path,
layer_name = layer_name,
symbol_table = symbol_table,
hive_offsets = hive_offsets):
for hive in hivelist.HiveList.list_hives(self.context,
self.config_path,
layer_name = layer_name,
symbol_table = symbol_table,
hive_offsets = hive_offsets):
try:
# Walk it
@@ -164,12 +168,10 @@ class PrintKey(interfaces.plugins.PluginInterface):
def run(self):
offset = self.config.get('offset', None)
return TreeGrid(
columns = [('Last Write Time', datetime.datetime), ('Hive Offset', format_hints.Hex), ('Type', str),
('Key', str), ('Name', str), ('Data', str), ('Volatile', bool)],
generator = self._registry_walker(
self.config['primary'],
self.config['nt_symbols'],
hive_offsets = None if offset is None else [offset],
key = self.config.get('key', None),
recurse = self.config.get('recurse', None)))
return TreeGrid(columns = [('Last Write Time', datetime.datetime), ('Hive Offset', format_hints.Hex),
('Type', str), ('Key', str), ('Name', str), ('Data', str), ('Volatile', bool)],
generator = self._registry_walker(self.config['primary'],
self.config['nt_symbols'],
hive_offsets = None if offset is None else [offset],
key = self.config.get('key', None),
recurse = self.config.get('recurse', None)))
@@ -36,8 +36,9 @@ class UserAssist(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.IntRequirement(name = 'offset', description = "Hive Offset", default = None, optional = True),
requirements.PluginRequirement(name = 'hivelist', plugin = hivelist.HiveList, version = (1, 0, 0))
@@ -130,8 +131,8 @@ class UserAssist(interfaces.plugins.PluginInterface):
self._determine_userassist_type()
userassist_node_path = hive.get_key(
"software\\microsoft\\windows\\currentversion\\explorer\\userassist", return_list = True)
userassist_node_path = hive.get_key("software\\microsoft\\windows\\currentversion\\explorer\\userassist",
return_list = True)
if not userassist_node_path:
vollog.warning("list_userassist did not find a valid node_path (or None)")
@@ -215,13 +216,12 @@ class UserAssist(interfaces.plugins.PluginInterface):
hive_offsets = [self.config.get('offset', None)]
# get all the user hive offsets or use the one specified
for hive in hivelist.HiveList.list_hives(
context = self.context,
base_config_path = self.config_path,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_string = 'ntuser.dat',
hive_offsets = hive_offsets):
for hive in hivelist.HiveList.list_hives(context = self.context,
base_config_path = self.config_path,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_string = 'ntuser.dat',
hive_offsets = hive_offsets):
try:
yield from self.list_userassist(hive)
continue
+13 -9
View File
@@ -24,8 +24,9 @@ class SSDT(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.PluginRequirement(name = 'modules', plugin = modules.Modules, version = (1, 0, 0)),
]
@@ -61,8 +62,12 @@ class SSDT(plugins.PluginInterface):
if module_name in windows_constants.KERNEL_MODULE_NAMES:
symbol_table_name = symbol_table
context_module = contexts.SizedModule(
context, module_name, layer_name, mod.DllBase, mod.SizeOfImage, symbol_table_name = symbol_table_name)
context_module = contexts.SizedModule(context,
module_name,
layer_name,
mod.DllBase,
mod.SizeOfImage,
symbol_table_name = symbol_table_name)
context_modules.append(context_module)
@@ -102,11 +107,10 @@ class SSDT(plugins.PluginInterface):
find_address = passthrough
functions = ntkrnlmp.object(
object_type = "array",
offset = service_table_address,
subtype = ntkrnlmp.get_type(array_subtype),
count = service_limit)
functions = ntkrnlmp.object(object_type = "array",
offset = service_table_address,
subtype = ntkrnlmp.get_type(array_subtype),
count = service_limit)
for idx, function_obj in enumerate(functions):
@@ -21,8 +21,9 @@ class Strings(interfaces.plugins.PluginInterface):
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.URIRequirement(name = "strings_file", description = "Strings file")
]
+40 -44
View File
@@ -21,33 +21,34 @@ class SvcScan(interfaces.plugins.PluginInterface):
_version = (1, 0, 0)
is_vista_or_later = poolscanner.os_distinguisher(
version_check = lambda x: x >= (6, 0), fallback_checks = [("KdCopyDataBlock", None, True)])
is_vista_or_later = poolscanner.os_distinguisher(version_check = lambda x: x >= (6, 0),
fallback_checks = [("KdCopyDataBlock", None, True)])
is_windows_xp = poolscanner.os_distinguisher(
version_check = lambda x: (5, 1) <= x < (5, 2),
fallback_checks = [("KdCopyDataBlock", None, False), ("_HANDLE_TABLE", "HandleCount", True)])
is_windows_xp = poolscanner.os_distinguisher(version_check = lambda x: (5, 1) <= x < (5, 2),
fallback_checks = [("KdCopyDataBlock", None, False),
("_HANDLE_TABLE", "HandleCount", True)])
is_xp_or_2003 = poolscanner.os_distinguisher(
version_check = lambda x: (5, 1) <= x < (6, 0),
fallback_checks = [("KdCopyDataBlock", None, False), ("_HANDLE_TABLE", "HandleCount", True)])
is_xp_or_2003 = poolscanner.os_distinguisher(version_check = lambda x: (5, 1) <= x < (6, 0),
fallback_checks = [("KdCopyDataBlock", None, False),
("_HANDLE_TABLE", "HandleCount", True)])
is_win10_up_to_15063 = poolscanner.os_distinguisher(
version_check = lambda x: (10, 0) <= x < (10, 0, 16299),
fallback_checks = [("ObHeaderCookie", None, True), ("_HANDLE_TABLE", "HandleCount", False),
("ObHeaderCookie", None, True)])
is_win10_up_to_15063 = poolscanner.os_distinguisher(version_check = lambda x: (10, 0) <= x < (10, 0, 16299),
fallback_checks = [("ObHeaderCookie", None, True),
("_HANDLE_TABLE", "HandleCount", False),
("ObHeaderCookie", None, True)])
is_win10_16299_or_later = poolscanner.os_distinguisher(
version_check = lambda x: x >= (10, 0, 16299),
fallback_checks = [("ObHeaderCookie", None, True), ("_HANDLE_TABLE", "HandleCount", False),
("ObHeaderCookie", None, True)])
is_win10_16299_or_later = poolscanner.os_distinguisher(version_check = lambda x: x >= (10, 0, 16299),
fallback_checks = [("ObHeaderCookie", None, True),
("_HANDLE_TABLE", "HandleCount", False),
("ObHeaderCookie", None, True)])
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
requirements.PluginRequirement(name = 'poolscanner', plugin = poolscanner.PoolScanner, version = (1, 0, 0)),
@@ -82,8 +83,8 @@ class SvcScan(interfaces.plugins.PluginInterface):
symbol_filename = "services-xp-2003-x64"
elif poolscanner.PoolScanner.is_windows_8_or_later(context = context, symbol_table = symbol_table) and is_64bit:
symbol_filename = "services-win8-x64"
elif poolscanner.PoolScanner.is_windows_8_or_later(
context = context, symbol_table = symbol_table) and not is_64bit:
elif poolscanner.PoolScanner.is_windows_8_or_later(context = context,
symbol_table = symbol_table) and not is_64bit:
symbol_filename = "services-win8-x86"
elif SvcScan.is_win10_up_to_15063(context = context, symbol_table = symbol_table) and is_64bit:
symbol_filename = "services-win10-15063-x64"
@@ -100,13 +101,12 @@ class SvcScan(interfaces.plugins.PluginInterface):
else:
raise NotImplementedError("This version of Windows is not supported!")
return intermed.IntermediateSymbolTable.create(
context,
config_path,
"windows",
symbol_filename,
class_types = services.class_types,
native_types = native_types)
return intermed.IntermediateSymbolTable.create(context,
config_path,
"windows",
symbol_filename,
class_types = services.class_types,
native_types = native_types)
def _generator(self):
@@ -126,35 +126,31 @@ class SvcScan(interfaces.plugins.PluginInterface):
seen = []
for task in pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func):
for task in pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func):
proc_layer_name = task.add_process_layer()
layer = self.context.layers[proc_layer_name]
for offset in layer.scan(
context = self.context,
scanner = scanners.BytesScanner(needle = service_tag),
sections = vadyarascan.VadYaraScan.get_vad_maps(task)):
for offset in layer.scan(context = self.context,
scanner = scanners.BytesScanner(needle = service_tag),
sections = vadyarascan.VadYaraScan.get_vad_maps(task)):
if not is_vista_or_later:
service_record = self.context.object(
service_table_name + constants.BANG + "_SERVICE_RECORD",
offset = offset - relative_tag_offset,
layer_name = proc_layer_name)
service_record = self.context.object(service_table_name + constants.BANG + "_SERVICE_RECORD",
offset = offset - relative_tag_offset,
layer_name = proc_layer_name)
if not service_record.is_valid():
continue
yield (0, self.get_record_tuple(service_record))
else:
service_header = self.context.object(
service_table_name + constants.BANG + "_SERVICE_HEADER",
offset = offset,
layer_name = proc_layer_name)
service_header = self.context.object(service_table_name + constants.BANG + "_SERVICE_HEADER",
offset = offset,
layer_name = proc_layer_name)
if not service_header.is_valid():
continue
@@ -18,8 +18,9 @@ class SymlinkScan(plugins.PluginInterface, timeliner.TimeLinerInterface):
@classmethod
def get_requirements(cls):
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -79,8 +79,7 @@ class VadDump(interfaces_plugins.PluginInterface):
return renderers.TreeGrid([("PID", int), ("Process", str), ("Result", str)],
self._generator(
pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
@@ -126,8 +126,7 @@ class VadInfo(interfaces.plugins.PluginInterface):
("Protection", str), ("CommitCharge", int), ("PrivateMemory", int),
("Parent", format_hints.Hex), ("File", str)],
self._generator(
pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func)))
@@ -26,22 +26,26 @@ class VadYaraScan(interfaces.plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = "Memory layer for the kernel", architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = "Memory layer for the kernel",
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
requirements.BooleanRequirement(
name = "wide", description = "Match wide (unicode) strings", default = False, optional = True),
requirements.StringRequirement(
name = "yara_rules", description = "Yara rules (as a string)", optional = True),
requirements.BooleanRequirement(name = "wide",
description = "Match wide (unicode) strings",
default = False,
optional = True),
requirements.StringRequirement(name = "yara_rules",
description = "Yara rules (as a string)",
optional = True),
requirements.URIRequirement(name = "yara_file", description = "Yara rules (as a file)", optional = True),
requirements.IntRequirement(
name = "max_size",
default = 0x40000000,
description = "Set the maximum size (default is 1GB)",
optional = True),
requirements.IntRequirement(name = "max_size",
default = 0x40000000,
description = "Set the maximum size (default is 1GB)",
optional = True),
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
requirements.IntRequirement(
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
requirements.IntRequirement(name = 'pid',
description = "Process ID to include (all other processes are excluded)",
optional = True)
]
def _generator(self):
@@ -64,15 +68,13 @@ class VadYaraScan(interfaces.plugins.PluginInterface):
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
for task in pslist.PsList.list_processes(
context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func):
for offset, name in layer.scan(
context = self.context,
scanner = yarascan.YaraScanner(rules = rules),
sections = self.get_vad_maps(task)):
for task in pslist.PsList.list_processes(context = self.context,
layer_name = self.config['primary'],
symbol_table = self.config['nt_symbols'],
filter_func = filter_func):
for offset, name in layer.scan(context = self.context,
scanner = yarascan.YaraScanner(rules = rules),
sections = self.get_vad_maps(task)):
yield format_hints.Hex(offset), name
@staticmethod
@@ -34,8 +34,9 @@ class VerInfo(interfaces_plugins.PluginInterface):
## TODO: and we don't want any CLI options from pslist, modules, or moddump
return [
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
]
@@ -56,8 +57,9 @@ class VerInfo(interfaces_plugins.PluginInterface):
pe_data = io.BytesIO()
dos_header = context.object(
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER", offset = base_address, layer_name = layer_name)
dos_header = context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
offset = base_address,
layer_name = layer_name)
for offset, data in dos_header.reconstruct():
pe_data.seek(offset)
@@ -94,8 +96,11 @@ class VerInfo(interfaces_plugins.PluginInterface):
session_layers: <generator> of layers in the session to be checked
"""
pe_table_name = intermed.IntermediateSymbolTable.create(
self.context, self.config_path, "windows", "pe", class_types = extensions.pe.class_types)
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
self.config_path,
"windows",
"pe",
class_types = extensions.pe.class_types)
for mod in mods:
try:
@@ -136,9 +141,10 @@ class VerInfo(interfaces_plugins.PluginInterface):
(major, minor, product, build) = [renderers.UnreadableValue()] * 4
yield (0, (proc.UniqueProcessId,
proc.ImageFileName.cast(
"string", max_length = proc.ImageFileName.vol.count, errors = "replace"),
format_hints.Hex(entry.DllBase), BaseDllName, major, minor, product, build))
proc.ImageFileName.cast("string",
max_length = proc.ImageFileName.vol.count,
errors = "replace"), format_hints.Hex(entry.DllBase), BaseDllName,
major, minor, product, build))
def run(self):
procs = pslist.PsList.list_processes(self.context, self.config["primary"], self.config["nt_symbols"])
+19 -15
View File
@@ -23,8 +23,9 @@ class VirtMap(interfaces.plugins.PluginInterface):
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
# Since we're calling the plugin, make sure we have the plugin's requirements
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
requirements.TranslationLayerRequirement(name = 'primary',
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
]
@@ -50,30 +51,32 @@ class VirtMap(interfaces.plugins.PluginInterface):
if module.has_symbol('MiVisibleState'):
symbol = module.get_symbol('MiVisibleState')
visible_state = module.object(
object_type = 'pointer', offset = symbol.address,
subtype = module.get_type('_MI_VISIBLE_STATE')).dereference()
visible_state = module.object(object_type = 'pointer',
offset = symbol.address,
subtype = module.get_type('_MI_VISIBLE_STATE')).dereference()
if hasattr(visible_state, 'SystemVaRegions'):
for i in range(visible_state.SystemVaRegions.count):
lookup = system_va_type.lookup(i)
region_range = result.get(lookup, [])
region_range.append((visible_state.SystemVaRegions[i].BaseAddress,
visible_state.SystemVaRegions[i].NumberOfBytes))
region_range.append(
(visible_state.SystemVaRegions[i].BaseAddress, visible_state.SystemVaRegions[i].NumberOfBytes))
result[lookup] = region_range
elif hasattr(visible_state, 'SystemVaType'):
system_range_start = module.object(
object_type = "pointer", offset = module.get_symbol("MmSystemRangeStart").address)
system_range_start = module.object(object_type = "pointer",
offset = module.get_symbol("MmSystemRangeStart").address)
result = cls._enumerate_system_va_type(large_page_size, system_range_start, module,
visible_state.SystemVaType)
else:
raise exceptions.SymbolError("Required structures not found")
elif module.has_symbol('MiSystemVaType'):
system_range_start = module.object(
object_type = "pointer", offset = module.get_symbol("MmSystemRangeStart").address)
system_range_start = module.object(object_type = "pointer",
offset = module.get_symbol("MmSystemRangeStart").address)
symbol = module.get_symbol('MiSystemVaType')
array_count = (0xFFFFFFFF + 1 - system_range_start) // large_page_size
type_array = module.object(
object_type = 'array', offset = symbol.address, count = array_count, subtype = module.get_type('char'))
type_array = module.object(object_type = 'array',
offset = symbol.address,
count = array_count,
subtype = module.get_type('char'))
result = cls._enumerate_system_va_type(large_page_size, system_range_start, module, type_array)
else:
@@ -114,8 +117,9 @@ class VirtMap(interfaces.plugins.PluginInterface):
def run(self):
layer = self.context.layers[self.config['primary']]
module = self.context.module(
self.config['nt_symbols'], layer_name = layer.name, offset = layer.config['kernel_virtual_offset'])
module = self.context.module(self.config['nt_symbols'],
layer_name = layer.name,
offset = layer.config['kernel_virtual_offset'])
return renderers.TreeGrid([("Region", str), ("Start offset", format_hints.Hex),
("End offset", format_hints.Hex)],
+26 -20
View File
@@ -40,27 +40,33 @@ class YaraScan(plugins.PluginInterface):
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(
name = 'primary', description = "Memory layer for the kernel", architectures = ["Intel32", "Intel64"]),
requirements.BooleanRequirement(
name = "all", description = "Scan both process and kernel memory", default = False, optional = True),
requirements.BooleanRequirement(
name = "insensitive",
description = "Makes the search case insensitive",
default = False,
optional = True),
requirements.BooleanRequirement(
name = "kernel", description = "Scan kernel modules", default = False, optional = True),
requirements.BooleanRequirement(
name = "wide", description = "Match wide (unicode) strings", default = False, optional = True),
requirements.StringRequirement(
name = "yara_rules", description = "Yara rules (as a string)", optional = True),
requirements.TranslationLayerRequirement(name = 'primary',
description = "Memory layer for the kernel",
architectures = ["Intel32", "Intel64"]),
requirements.BooleanRequirement(name = "all",
description = "Scan both process and kernel memory",
default = False,
optional = True),
requirements.BooleanRequirement(name = "insensitive",
description = "Makes the search case insensitive",
default = False,
optional = True),
requirements.BooleanRequirement(name = "kernel",
description = "Scan kernel modules",
default = False,
optional = True),
requirements.BooleanRequirement(name = "wide",
description = "Match wide (unicode) strings",
default = False,
optional = True),
requirements.StringRequirement(name = "yara_rules",
description = "Yara rules (as a string)",
optional = True),
requirements.URIRequirement(name = "yara_file", description = "Yara rules (as a file)", optional = True),
requirements.IntRequirement(
name = "max_size",
default = 0x40000000,
description = "Set the maximum size (default is 1GB)",
optional = True)
requirements.IntRequirement(name = "max_size",
default = 0x40000000,
description = "Set the maximum size (default is 1GB)",
optional = True)
]
def _generator(self):