mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 21:44:52 +02:00
Yapf-0.28.0 rerun across the whole codebase.
This commit is contained in:
@@ -20,10 +20,13 @@ class ConfigWriter(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.BooleanRequirement(
|
||||
name = 'extra', description = 'Outputs whole configuration tree', default = False, optional = True)
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.BooleanRequirement(name = 'extra',
|
||||
description = 'Outputs whole configuration tree',
|
||||
default = False,
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
|
||||
@@ -23,20 +23,21 @@ class LayerWriter(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.StringRequirement(
|
||||
name = 'layer_name', description = 'Name of the layer to write out', default = None, optional = True),
|
||||
requirements.StringRequirement(
|
||||
name = 'output',
|
||||
description = 'Filename to output the chosen layer',
|
||||
optional = True,
|
||||
default = cls.default_output_name),
|
||||
requirements.IntRequirement(
|
||||
name = 'block_size',
|
||||
description = "Size of blocks to copy over",
|
||||
default = cls.default_block_size,
|
||||
optional = True)
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.StringRequirement(name = 'layer_name',
|
||||
description = 'Name of the layer to write out',
|
||||
default = None,
|
||||
optional = True),
|
||||
requirements.StringRequirement(name = 'output',
|
||||
description = 'Filename to output the chosen layer',
|
||||
optional = True,
|
||||
default = cls.default_output_name),
|
||||
requirements.IntRequirement(name = 'block_size',
|
||||
description = "Size of blocks to copy over",
|
||||
default = cls.default_block_size,
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
|
||||
@@ -24,8 +24,9 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
]
|
||||
@@ -58,22 +59,19 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
bang_addrs = []
|
||||
|
||||
# find '#' values on the heap
|
||||
for address in proc_layer.scan(
|
||||
self.context,
|
||||
scanners.BytesScanner(b"#"),
|
||||
sections = task.get_process_memory_sections(heap_only = True)):
|
||||
for address in proc_layer.scan(self.context,
|
||||
scanners.BytesScanner(b"#"),
|
||||
sections = task.get_process_memory_sections(heap_only = True)):
|
||||
bang_addrs.append(struct.pack(pack_format, address))
|
||||
|
||||
history_entries = []
|
||||
|
||||
for address, _ in proc_layer.scan(
|
||||
self.context,
|
||||
scanners.MultiStringScanner(bang_addrs),
|
||||
sections = task.get_process_memory_sections(heap_only = True)):
|
||||
hist = self.context.object(
|
||||
bash_table_name + constants.BANG + "hist_entry",
|
||||
offset = address - ts_offset,
|
||||
layer_name = proc_layer_name)
|
||||
for address, _ in proc_layer.scan(self.context,
|
||||
scanners.MultiStringScanner(bang_addrs),
|
||||
sections = task.get_process_memory_sections(heap_only = True)):
|
||||
hist = self.context.object(bash_table_name + constants.BANG + "hist_entry",
|
||||
offset = address - ts_offset,
|
||||
layer_name = proc_layer_name)
|
||||
|
||||
if hist.is_valid():
|
||||
history_entries.append(hist)
|
||||
@@ -87,18 +85,19 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("CommandTime", datetime.datetime),
|
||||
("Command", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
def generate_timeline(self):
|
||||
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
|
||||
|
||||
for row in self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context, self.config['primary'], self.config['vmlinux'], filter_func = filter_func)):
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)):
|
||||
_depth, row_data = row
|
||||
description = "{} ({}): \"{}\"".format(row_data[0], row_data[1], row_data[3])
|
||||
yield (description, timeliner.TimeLinerType.CREATED, row_data[2])
|
||||
|
||||
@@ -22,8 +22,9 @@ class Check_afinfo(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
|
||||
]
|
||||
|
||||
@@ -63,8 +64,11 @@ class Check_afinfo(plugins.PluginInterface):
|
||||
def _generator(self):
|
||||
linux.LinuxUtilities.aslr_mask_symbol_table(self.context, self.config['vmlinux'], self.config['primary'])
|
||||
|
||||
vmlinux = contexts.Module(
|
||||
self.context, self.config['vmlinux'], self.config['primary'], 0, absolute_symbol_addresses = True)
|
||||
vmlinux = contexts.Module(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['primary'],
|
||||
0,
|
||||
absolute_symbol_addresses = True)
|
||||
|
||||
op_members = vmlinux.get_type('file_operations').members
|
||||
seq_members = vmlinux.get_type('seq_operations').members
|
||||
|
||||
@@ -29,8 +29,9 @@ class Check_syscall(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
|
||||
]
|
||||
|
||||
@@ -123,8 +124,11 @@ class Check_syscall(plugins.PluginInterface):
|
||||
def _generator(self):
|
||||
linux.LinuxUtilities.aslr_mask_symbol_table(self.context, self.config['vmlinux'], self.config['primary'])
|
||||
|
||||
vmlinux = contexts.Module(
|
||||
self.context, self.config['vmlinux'], self.config['primary'], 0, absolute_symbol_addresses = True)
|
||||
vmlinux = contexts.Module(self.context,
|
||||
self.config['vmlinux'],
|
||||
self.config['primary'],
|
||||
0,
|
||||
absolute_symbol_addresses = True)
|
||||
|
||||
ptr_sz = vmlinux.get_type("pointer").size
|
||||
if ptr_sz == 4:
|
||||
@@ -153,8 +157,10 @@ class Check_syscall(plugins.PluginInterface):
|
||||
tables.append(("32bit", ia32_info))
|
||||
|
||||
for (table_name, (tableaddr, tblsz)) in tables:
|
||||
table = vmlinux.object(
|
||||
object_type = "array", subtype = vmlinux.get_type("pointer"), offset = tableaddr, count = tblsz)
|
||||
table = vmlinux.object(object_type = "array",
|
||||
subtype = vmlinux.get_type("pointer"),
|
||||
offset = tableaddr,
|
||||
count = tblsz)
|
||||
|
||||
for (i, call_addr) in enumerate(table):
|
||||
if not call_addr:
|
||||
|
||||
@@ -20,8 +20,9 @@ class Elfs(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -51,8 +52,7 @@ class Elfs(plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Start", format_hints.Hex),
|
||||
("End", format_hints.Hex), ("File Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -21,8 +21,9 @@ class Lsmod(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
|
||||
]
|
||||
|
||||
|
||||
@@ -22,8 +22,9 @@ class Lsof(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -44,8 +45,7 @@ class Lsof(plugins.PluginInterface):
|
||||
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("FD", int), ("Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -20,8 +20,9 @@ class Malfind(interfaces_plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
|
||||
]
|
||||
|
||||
@@ -68,8 +69,7 @@ class Malfind(interfaces_plugins.PluginInterface):
|
||||
("End", format_hints.Hex), ("Protection", str), ("Hexdump", format_hints.HexBytes),
|
||||
("Disasm", interfaces_renderers.Disassembly)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -19,8 +19,9 @@ class Maps(plugins.PluginInterface):
|
||||
def get_requirements(cls):
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -60,8 +61,7 @@ class Maps(plugins.PluginInterface):
|
||||
("PgOff", format_hints.Hex), ("Major", int), ("Minor", int), ("Inode", int),
|
||||
("File Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -19,8 +19,9 @@ class PsList(interfaces_plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "vmlinux", description = "Linux kernel symbols")
|
||||
]
|
||||
|
||||
@@ -47,11 +48,10 @@ class PsList(interfaces_plugins.PluginInterface):
|
||||
return lambda _: False
|
||||
|
||||
def _generator(self):
|
||||
for task in self.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
|
||||
for task in self.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['vmlinux'],
|
||||
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
|
||||
pid = task.pid
|
||||
ppid = 0
|
||||
if task.parent:
|
||||
|
||||
@@ -24,8 +24,9 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -58,24 +59,23 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
bang_addrs = []
|
||||
|
||||
# find '#' values on the heap
|
||||
for address in proc_layer.scan(
|
||||
self.context,
|
||||
scanners.BytesScanner(b"#"),
|
||||
sections = task.get_process_memory_sections(self.context, self.config['darwin'],
|
||||
rw_no_file = True)):
|
||||
for address in proc_layer.scan(self.context,
|
||||
scanners.BytesScanner(b"#"),
|
||||
sections = task.get_process_memory_sections(self.context,
|
||||
self.config['darwin'],
|
||||
rw_no_file = True)):
|
||||
bang_addrs.append(struct.pack(pack_format, address))
|
||||
|
||||
history_entries = []
|
||||
|
||||
for address, _ in proc_layer.scan(
|
||||
self.context,
|
||||
scanners.MultiStringScanner(bang_addrs),
|
||||
sections = task.get_process_memory_sections(self.context, self.config['darwin'],
|
||||
rw_no_file = True)):
|
||||
hist = self.context.object(
|
||||
bash_table_name + constants.BANG + "hist_entry",
|
||||
offset = address - ts_offset,
|
||||
layer_name = proc_layer_name)
|
||||
for address, _ in proc_layer.scan(self.context,
|
||||
scanners.MultiStringScanner(bang_addrs),
|
||||
sections = task.get_process_memory_sections(self.context,
|
||||
self.config['darwin'],
|
||||
rw_no_file = True)):
|
||||
hist = self.context.object(bash_table_name + constants.BANG + "hist_entry",
|
||||
offset = address - ts_offset,
|
||||
layer_name = proc_layer_name)
|
||||
|
||||
if hist.is_valid():
|
||||
history_entries.append(hist)
|
||||
@@ -89,18 +89,19 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("CommandTime", datetime.datetime),
|
||||
("Command", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
def generate_timeline(self):
|
||||
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
|
||||
|
||||
for row in self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context, self.config['primary'], self.config['darwin'], filter_func = filter_func)):
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)):
|
||||
_depth, row_data = row
|
||||
description = "{} ({}): \"{}\"".format(row_data[0], row_data[1], row_data[3])
|
||||
yield (description, timeliner.TimeLinerType.CREATED, row_data[2])
|
||||
|
||||
@@ -20,8 +20,9 @@ class Check_syscall(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
|
||||
]
|
||||
|
||||
|
||||
@@ -22,8 +22,9 @@ class Check_sysctl(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
|
||||
]
|
||||
|
||||
|
||||
@@ -21,8 +21,9 @@ class Check_trap_table(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
|
||||
]
|
||||
|
||||
|
||||
@@ -19,8 +19,9 @@ class Lsmod(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Linux kernel symbols")
|
||||
]
|
||||
|
||||
|
||||
@@ -19,8 +19,9 @@ class lsof(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Kernel Address Space', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Kernel Address Space',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac Kernel"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -38,8 +39,7 @@ class lsof(plugins.PluginInterface):
|
||||
|
||||
return renderers.TreeGrid([("PID", int), ("File Descriptor", int), ("File Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -18,8 +18,9 @@ class Malfind(interfaces_plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Linux kernel symbols")
|
||||
]
|
||||
|
||||
@@ -66,8 +67,7 @@ class Malfind(interfaces_plugins.PluginInterface):
|
||||
("End", format_hints.Hex), ("Protection", str), ("Hexdump", format_hints.HexBytes),
|
||||
("Disasm", interfaces_renderers.Disassembly)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -21,8 +21,9 @@ class Netstat(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Kernel Address Space', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Kernel Address Space',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac Kernel"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -78,8 +79,7 @@ class Netstat(plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("Offset", format_hints.Hex), ("Proto", str), ("Local IP", str), ("Local Port", int),
|
||||
("Remote IP", str), ("Remote Port", int), ("State", str), ("Process", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -17,8 +17,9 @@ class Maps(interfaces_plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Linux kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -42,8 +43,7 @@ class Maps(interfaces_plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Start", format_hints.Hex),
|
||||
("End", format_hints.Hex), ("Protection", str), ("Map Name", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -17,8 +17,9 @@ class Psaux(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
@@ -89,8 +90,7 @@ class Psaux(plugins.PluginInterface):
|
||||
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Argc", int), ("Arguments", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -21,8 +21,9 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols")
|
||||
]
|
||||
|
||||
@@ -42,11 +43,10 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
return filter_func
|
||||
|
||||
def _generator(self):
|
||||
for task in self.list_tasks(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
|
||||
for task in self.list_tasks(self.context,
|
||||
self.config['primary'],
|
||||
self.config['darwin'],
|
||||
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
|
||||
pid = task.p_pid
|
||||
ppid = task.p_ppid
|
||||
name = utility.array_to_string(task.p_comm)
|
||||
|
||||
@@ -22,8 +22,9 @@ class PsTree(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0))
|
||||
]
|
||||
|
||||
@@ -23,8 +23,9 @@ class Check_syscall(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "darwin", description = "Mac kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (1, 0, 0))
|
||||
]
|
||||
@@ -36,11 +37,10 @@ class Check_syscall(plugins.PluginInterface):
|
||||
|
||||
policy_list = kernel.object_from_symbol(symbol_name = "_mac_policy_list").cast("mac_policy_list")
|
||||
|
||||
entries = kernel.object(
|
||||
object_type = "array",
|
||||
offset = policy_list.entries.dereference().vol.offset,
|
||||
subtype = kernel.get_type('mac_policy_list_element'),
|
||||
count = policy_list.staticmax + 1)
|
||||
entries = kernel.object(object_type = "array",
|
||||
offset = policy_list.entries.dereference().vol.offset,
|
||||
subtype = kernel.get_type('mac_policy_list_element'),
|
||||
count = policy_list.staticmax + 1)
|
||||
|
||||
mask = self.context.layers[self.config['primary']].address_mask
|
||||
mods_list = [(mod.name, mod.address & mask, (mod.address & mask) + mod.size) for mod in mods]
|
||||
|
||||
@@ -72,11 +72,10 @@ class Timeliner(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.StringRequirement(
|
||||
name = 'plugins',
|
||||
description = "Comma separated list of plugins to run",
|
||||
optional = True,
|
||||
default = None),
|
||||
requirements.StringRequirement(name = 'plugins',
|
||||
description = "Comma separated list of plugins to run",
|
||||
optional = True,
|
||||
default = None),
|
||||
requirements.BooleanRequirement(
|
||||
name = 'record-config',
|
||||
description = "Whether to record the state of all the plugins once complete",
|
||||
@@ -150,11 +149,10 @@ class Timeliner(interfaces.plugins.PluginInterface):
|
||||
json.dump(total_config, fp, sort_keys = True, indent = 2)
|
||||
self.produce_file(filedata)
|
||||
|
||||
return renderers.TreeGrid(
|
||||
columns = [("Plugin", str), ("Description", str), ("Created Date", datetime.datetime),
|
||||
("Modified Date", datetime.datetime), ("Accessed Date", datetime.datetime),
|
||||
("Changed Date", datetime.datetime)],
|
||||
generator = self._generator(runable_plugins))
|
||||
return renderers.TreeGrid(columns = [("Plugin", str), ("Description", str), ("Created Date", datetime.datetime),
|
||||
("Modified Date", datetime.datetime), ("Accessed Date", datetime.datetime),
|
||||
("Changed Date", datetime.datetime)],
|
||||
generator = self._generator(runable_plugins))
|
||||
|
||||
def build_configuration(self):
|
||||
"""Builds the configuration to save for the plugin such that it can be
|
||||
|
||||
@@ -24,8 +24,9 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'ssdt', plugin = ssdt.SSDT, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'svcscan', plugin = svcscan.SvcScan, version = (1, 0, 0))
|
||||
@@ -52,13 +53,12 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
else:
|
||||
symbol_filename = "callbacks-x86"
|
||||
|
||||
return intermed.IntermediateSymbolTable.create(
|
||||
context,
|
||||
config_path,
|
||||
"windows",
|
||||
symbol_filename,
|
||||
native_types = native_types,
|
||||
table_mapping = table_mapping)
|
||||
return intermed.IntermediateSymbolTable.create(context,
|
||||
config_path,
|
||||
"windows",
|
||||
symbol_filename,
|
||||
native_types = native_types,
|
||||
table_mapping = table_mapping)
|
||||
|
||||
@classmethod
|
||||
def list_notify_routines(cls, context: interfaces.context.ContextInterface, layer_name: str, symbol_table: str,
|
||||
@@ -97,11 +97,10 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
else:
|
||||
count = 8
|
||||
|
||||
fast_refs = ntkrnlmp.object(
|
||||
object_type = "array",
|
||||
offset = symbol_offset,
|
||||
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
|
||||
count = count)
|
||||
fast_refs = ntkrnlmp.object(object_type = "array",
|
||||
offset = symbol_offset,
|
||||
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
|
||||
count = count)
|
||||
|
||||
for fast_ref in fast_refs:
|
||||
try:
|
||||
@@ -143,11 +142,10 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
if callback_count == 0:
|
||||
return
|
||||
|
||||
fast_refs = ntkrnlmp.object(
|
||||
object_type = "array",
|
||||
offset = symbol_offset,
|
||||
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
|
||||
count = callback_count)
|
||||
fast_refs = ntkrnlmp.object(object_type = "array",
|
||||
offset = symbol_offset,
|
||||
subtype = ntkrnlmp.get_type("_EX_FAST_REF"),
|
||||
count = callback_count)
|
||||
|
||||
for fast_ref in fast_refs:
|
||||
try:
|
||||
@@ -183,8 +181,9 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
return
|
||||
|
||||
full_type_name = callback_table_name + constants.BANG + "_KBUGCHECK_REASON_CALLBACK_RECORD"
|
||||
callback_record = context.object(
|
||||
object_type = full_type_name, offset = kvo + list_offset, layer_name = layer_name)
|
||||
callback_record = context.object(object_type = full_type_name,
|
||||
offset = kvo + list_offset,
|
||||
layer_name = layer_name)
|
||||
|
||||
for callback in callback_record.Entry:
|
||||
|
||||
@@ -233,12 +232,11 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
continue
|
||||
|
||||
try:
|
||||
component = context.object(
|
||||
symbol_table + constants.BANG + "string",
|
||||
layer_name = layer_name,
|
||||
offset = callback.Component,
|
||||
max_length = 64,
|
||||
errors = "replace")
|
||||
component = context.object(symbol_table + constants.BANG + "string",
|
||||
layer_name = layer_name,
|
||||
offset = callback.Component,
|
||||
max_length = 64,
|
||||
errors = "replace")
|
||||
except exceptions.InvalidAddressException:
|
||||
component = renderers.UnreadableValue()
|
||||
|
||||
|
||||
@@ -18,12 +18,14 @@ class CmdLine(interfaces_plugins.PluginInterface):
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
requirements.IntRequirement(
|
||||
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
|
||||
requirements.IntRequirement(name = 'pid',
|
||||
description = "Process ID to include (all other processes are excluded)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _generator(self, procs):
|
||||
@@ -34,10 +36,9 @@ class CmdLine(interfaces_plugins.PluginInterface):
|
||||
proc_layer_name = proc.add_process_layer()
|
||||
|
||||
try:
|
||||
peb = self._context.object(
|
||||
self.config["nt_symbols"] + constants.BANG + "_PEB",
|
||||
layer_name = proc_layer_name,
|
||||
offset = proc.Peb)
|
||||
peb = self._context.object(self.config["nt_symbols"] + constants.BANG + "_PEB",
|
||||
layer_name = proc_layer_name,
|
||||
offset = proc.Peb)
|
||||
|
||||
result_text = peb.ProcessParameters.CommandLine.get_string()
|
||||
|
||||
@@ -54,8 +55,7 @@ class CmdLine(interfaces_plugins.PluginInterface):
|
||||
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Args", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -43,8 +43,11 @@ class DllDump(interfaces_plugins.PluginInterface):
|
||||
]
|
||||
|
||||
def _generator(self, procs):
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(
|
||||
self.context, self.config_path, "windows", "pe", class_types = extensions.pe.class_types)
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
|
||||
self.config_path,
|
||||
"windows",
|
||||
"pe",
|
||||
class_types = extensions.pe.class_types)
|
||||
|
||||
filter_func = lambda _: False
|
||||
if self.config.get('address', None) is not None:
|
||||
@@ -80,10 +83,9 @@ class DllDump(interfaces_plugins.PluginInterface):
|
||||
filedata = interfaces_plugins.FileInterface("pid.{0}.{1}.{2:#x}.dmp".format(
|
||||
proc.UniqueProcessId, ntpath.basename(vad.get_file_name()), vad.get_start()))
|
||||
|
||||
dos_header = self.context.object(
|
||||
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = vad.get_start(),
|
||||
layer_name = proc_layer_name)
|
||||
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = vad.get_start(),
|
||||
layer_name = proc_layer_name)
|
||||
|
||||
for offset, data in dos_header.reconstruct():
|
||||
filedata.data.seek(offset)
|
||||
@@ -101,8 +103,7 @@ class DllDump(interfaces_plugins.PluginInterface):
|
||||
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Result", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -18,12 +18,14 @@ class DllList(interfaces_plugins.PluginInterface):
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
requirements.IntRequirement(
|
||||
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
|
||||
requirements.IntRequirement(name = 'pid',
|
||||
description = "Process ID to include (all other processes are excluded)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _generator(self, procs):
|
||||
@@ -41,10 +43,10 @@ class DllList(interfaces_plugins.PluginInterface):
|
||||
pass
|
||||
|
||||
yield (0, (proc.UniqueProcessId,
|
||||
proc.ImageFileName.cast(
|
||||
"string", max_length = proc.ImageFileName.vol.count, errors = 'replace'),
|
||||
format_hints.Hex(entry.DllBase), format_hints.Hex(entry.SizeOfImage), BaseDllName,
|
||||
FullDllName))
|
||||
proc.ImageFileName.cast("string",
|
||||
max_length = proc.ImageFileName.vol.count,
|
||||
errors = 'replace'), format_hints.Hex(entry.DllBase),
|
||||
format_hints.Hex(entry.SizeOfImage), BaseDllName, FullDllName))
|
||||
|
||||
def run(self):
|
||||
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
|
||||
@@ -52,8 +54,7 @@ class DllList(interfaces_plugins.PluginInterface):
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Base", format_hints.Hex),
|
||||
("Size", format_hints.Hex), ("Name", str), ("Path", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -28,8 +28,9 @@ class DriverIrp(plugins.PluginInterface):
|
||||
return [
|
||||
requirements.PluginRequirement(name = 'ssdt', plugin = ssdt.SSDT, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'driverscan', plugin = driverscan.DriverScan, version = (1, 0, 0)),
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -20,8 +20,9 @@ class DriverScan(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -18,8 +18,9 @@ class FileScan(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -37,11 +37,13 @@ class Handles(interfaces_plugins.PluginInterface):
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.IntRequirement(
|
||||
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
|
||||
requirements.IntRequirement(name = 'pid',
|
||||
description = "Process ID to include (all other processes are excluded)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _decode_pointer(self, value, magic):
|
||||
@@ -86,8 +88,9 @@ class Handles(interfaces_plugins.PluginInterface):
|
||||
|
||||
offset = self._decode_pointer(handle_table_entry.LowValue, magic)
|
||||
# print("LowValue: {0:#x} Magic: {1:#x} Offset: {2:#x}".format(handle_table_entry.InfoTable, magic, offset))
|
||||
object_header = self.context.object(
|
||||
self.config["nt_symbols"] + constants.BANG + "_OBJECT_HEADER", virtual, offset = offset)
|
||||
object_header = self.context.object(self.config["nt_symbols"] + constants.BANG + "_OBJECT_HEADER",
|
||||
virtual,
|
||||
offset = offset)
|
||||
object_header.GrantedAccess = handle_table_entry.GrantedAccessBits
|
||||
|
||||
object_header.HandleValue = handle_value
|
||||
@@ -163,8 +166,10 @@ class Handles(interfaces_plugins.PluginInterface):
|
||||
except exceptions.SymbolError:
|
||||
table_addr = ntkrnlmp.get_symbol("ObpObjectTypes").address
|
||||
|
||||
ptrs = ntkrnlmp.object(
|
||||
object_type = "array", offset = table_addr, subtype = ntkrnlmp.get_type("pointer"), count = 100)
|
||||
ptrs = ntkrnlmp.object(object_type = "array",
|
||||
offset = table_addr,
|
||||
subtype = ntkrnlmp.get_type("pointer"),
|
||||
count = 100)
|
||||
|
||||
for i, ptr in enumerate(ptrs): # type: ignore
|
||||
# the first entry in the table is always null. break the
|
||||
@@ -216,8 +221,11 @@ class Handles(interfaces_plugins.PluginInterface):
|
||||
if not self.context.layers[virtual].is_valid(offset):
|
||||
return
|
||||
|
||||
table = ntkrnlmp.object(
|
||||
object_type = "array", offset = offset, subtype = subtype, count = int(count), absolute = True)
|
||||
table = ntkrnlmp.object(object_type = "array",
|
||||
offset = offset,
|
||||
subtype = subtype,
|
||||
count = int(count),
|
||||
absolute = True)
|
||||
|
||||
layer_object = self.context.layers[virtual]
|
||||
masked_offset = (offset & layer_object.maximum_address)
|
||||
@@ -232,8 +240,8 @@ class Handles(interfaces_plugins.PluginInterface):
|
||||
handle_multiplier = 4
|
||||
handle_level_base = depth * count * handle_multiplier
|
||||
|
||||
handle_value = (
|
||||
(entry.vol.offset - masked_offset) / (subtype.size / handle_multiplier)) + handle_level_base
|
||||
handle_value = ((entry.vol.offset - masked_offset) /
|
||||
(subtype.size / handle_multiplier)) + handle_level_base
|
||||
|
||||
item = self._get_item(entry, handle_value)
|
||||
|
||||
@@ -263,10 +271,12 @@ class Handles(interfaces_plugins.PluginInterface):
|
||||
|
||||
def _generator(self, procs):
|
||||
|
||||
type_map = self.get_type_map(
|
||||
context = self.context, layer_name = self.config["primary"], symbol_table = self.config["nt_symbols"])
|
||||
cookie = self.find_cookie(
|
||||
context = self.context, layer_name = self.config["primary"], symbol_table = self.config["nt_symbols"])
|
||||
type_map = self.get_type_map(context = self.context,
|
||||
layer_name = self.config["primary"],
|
||||
symbol_table = self.config["nt_symbols"])
|
||||
cookie = self.find_cookie(context = self.context,
|
||||
layer_name = self.config["primary"],
|
||||
symbol_table = self.config["nt_symbols"])
|
||||
|
||||
for proc in procs:
|
||||
|
||||
@@ -321,8 +331,7 @@ class Handles(interfaces_plugins.PluginInterface):
|
||||
("HandleValue", format_hints.Hex), ("Type", str),
|
||||
("GrantedAccess", format_hints.Hex), ("Name", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(self.context,
|
||||
self.config['primary'],
|
||||
self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -20,8 +20,9 @@ class Info(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
|
||||
]
|
||||
|
||||
@@ -57,16 +58,18 @@ class Info(plugins.PluginInterface):
|
||||
|
||||
native_types = self.context.symbol_space[self.config["nt_symbols"]].natives
|
||||
|
||||
kdbg_table_name = intermed.IntermediateSymbolTable.create(
|
||||
self.context,
|
||||
self.config_path,
|
||||
"windows",
|
||||
"kdbg",
|
||||
native_types = native_types,
|
||||
class_types = extensions.kdbg.class_types)
|
||||
kdbg_table_name = intermed.IntermediateSymbolTable.create(self.context,
|
||||
self.config_path,
|
||||
"windows",
|
||||
"kdbg",
|
||||
native_types = native_types,
|
||||
class_types = extensions.kdbg.class_types)
|
||||
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(
|
||||
self.context, self.config_path, "windows", "pe", class_types = extensions.pe.class_types)
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
|
||||
self.config_path,
|
||||
"windows",
|
||||
"pe",
|
||||
class_types = extensions.pe.class_types)
|
||||
|
||||
kvo = virtual_layer.config["kernel_virtual_offset"]
|
||||
|
||||
@@ -74,10 +77,9 @@ class Info(plugins.PluginInterface):
|
||||
|
||||
kdbg_offset = ntkrnlmp.get_symbol("KdDebuggerDataBlock").address
|
||||
|
||||
kdbg = self.context.object(
|
||||
kdbg_table_name + constants.BANG + "_KDDEBUGGER_DATA64",
|
||||
offset = kvo + kdbg_offset,
|
||||
layer_name = virtual_layer_name)
|
||||
kdbg = self.context.object(kdbg_table_name + constants.BANG + "_KDDEBUGGER_DATA64",
|
||||
offset = kvo + kdbg_offset,
|
||||
layer_name = virtual_layer_name)
|
||||
|
||||
yield (0, ("Kernel Base", hex(self.config["primary.kernel_virtual_offset"])))
|
||||
yield (0, ("DTB", hex(self.config["primary.page_map_offset"])))
|
||||
@@ -94,8 +96,9 @@ class Info(plugins.PluginInterface):
|
||||
|
||||
vers_offset = ntkrnlmp.get_symbol("KdVersionBlock").address
|
||||
|
||||
vers = ntkrnlmp.object(
|
||||
object_type = "_DBGKD_GET_VERSION64", layer_name = virtual_layer_name, offset = vers_offset)
|
||||
vers = ntkrnlmp.object(object_type = "_DBGKD_GET_VERSION64",
|
||||
layer_name = virtual_layer_name,
|
||||
offset = vers_offset)
|
||||
|
||||
yield (0, ("KdVersionBlock", hex(vers.vol.offset)))
|
||||
yield (0, ("Major/Minor", "{0}.{1}".format(vers.MajorVersion, vers.MinorVersion)))
|
||||
@@ -103,8 +106,9 @@ class Info(plugins.PluginInterface):
|
||||
|
||||
cpu_count_offset = ntkrnlmp.get_symbol("KeNumberProcessors").address
|
||||
|
||||
cpu_count = ntkrnlmp.object(
|
||||
object_type = "unsigned int", layer_name = virtual_layer_name, offset = cpu_count_offset)
|
||||
cpu_count = ntkrnlmp.object(object_type = "unsigned int",
|
||||
layer_name = virtual_layer_name,
|
||||
offset = cpu_count_offset)
|
||||
|
||||
yield (0, ("KeNumberProcessors", str(cpu_count)))
|
||||
|
||||
@@ -114,8 +118,10 @@ class Info(plugins.PluginInterface):
|
||||
else:
|
||||
kuser_addr = 0xFFFFF78000000000
|
||||
|
||||
kuser = ntkrnlmp.object(
|
||||
object_type = "_KUSER_SHARED_DATA", layer_name = virtual_layer_name, offset = kuser_addr, absolute = True)
|
||||
kuser = ntkrnlmp.object(object_type = "_KUSER_SHARED_DATA",
|
||||
layer_name = virtual_layer_name,
|
||||
offset = kuser_addr,
|
||||
absolute = True)
|
||||
|
||||
yield (0, ("SystemTime", str(kuser.SystemTime.get_time())))
|
||||
yield (0, ("NtSystemRoot",
|
||||
@@ -126,8 +132,9 @@ class Info(plugins.PluginInterface):
|
||||
# yield (0, ("KdDebuggerEnabled", "True" if kuser.KdDebuggerEnabled else "False"))
|
||||
# yield (0, ("SafeBootMode", "True" if kuser.SafeBootMode else "False"))
|
||||
|
||||
dos_header = self.context.object(
|
||||
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER", offset = kvo, layer_name = virtual_layer_name)
|
||||
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = kvo,
|
||||
layer_name = virtual_layer_name)
|
||||
|
||||
nt_header = dos_header.get_nt_header()
|
||||
|
||||
|
||||
@@ -20,11 +20,13 @@ class Malfind(interfaces.plugins.PluginInterface):
|
||||
def get_requirements(cls):
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.IntRequirement(
|
||||
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
|
||||
requirements.IntRequirement(name = 'pid',
|
||||
description = "Process ID to include (all other processes are excluded)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
@classmethod
|
||||
@@ -125,8 +127,7 @@ class Malfind(interfaces.plugins.PluginInterface):
|
||||
("CommitCharge", int), ("PrivateMemory", int), ("Hexdump", format_hints.HexBytes),
|
||||
("Disasm", interfaces.renderers.Disassembly)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -26,8 +26,9 @@ class ModDump(interfaces.plugins.PluginInterface):
|
||||
return [
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'modules', plugin = modules.Modules, version = (1, 0, 0)),
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
|
||||
]
|
||||
|
||||
@@ -53,15 +54,18 @@ class ModDump(interfaces.plugins.PluginInterface):
|
||||
seen_ids = [] # type: List[interfaces.objects.ObjectInterface]
|
||||
filter_func = pslist.PsList.create_pid_filter(pids or [])
|
||||
|
||||
for proc in pslist.PsList.list_processes(
|
||||
context = context, layer_name = layer_name, symbol_table = symbol_table, filter_func = filter_func):
|
||||
for proc in pslist.PsList.list_processes(context = context,
|
||||
layer_name = layer_name,
|
||||
symbol_table = symbol_table,
|
||||
filter_func = filter_func):
|
||||
proc_layer_name = proc.add_process_layer()
|
||||
|
||||
try:
|
||||
# create the session space object in the process' own layer.
|
||||
# not all processes have a valid session pointer.
|
||||
session_space = context.object(
|
||||
symbol_table + constants.BANG + "_MM_SESSION_SPACE", layer_name = layer_name, offset = proc.Session)
|
||||
session_space = context.object(symbol_table + constants.BANG + "_MM_SESSION_SPACE",
|
||||
layer_name = layer_name,
|
||||
offset = proc.Session)
|
||||
|
||||
if session_space.SessionId in seen_ids:
|
||||
continue
|
||||
@@ -101,8 +105,11 @@ class ModDump(interfaces.plugins.PluginInterface):
|
||||
def _generator(self, mods):
|
||||
|
||||
session_layers = list(self.get_session_layers(self.context, self.config['primary'], self.config['nt_symbols']))
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(
|
||||
self.context, self.config_path, "windows", "pe", class_types = pe.class_types)
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
|
||||
self.config_path,
|
||||
"windows",
|
||||
"pe",
|
||||
class_types = pe.class_types)
|
||||
|
||||
for mod in mods:
|
||||
try:
|
||||
@@ -115,10 +122,9 @@ class ModDump(interfaces.plugins.PluginInterface):
|
||||
result_text = "Cannot find a viable session layer for {0:#x}".format(mod.DllBase)
|
||||
else:
|
||||
try:
|
||||
dos_header = self.context.object(
|
||||
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = mod.DllBase,
|
||||
layer_name = session_layer_name)
|
||||
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = mod.DllBase,
|
||||
layer_name = session_layer_name)
|
||||
|
||||
filedata = interfaces.plugins.FileInterface("module.{0:#x}.dmp".format(mod.DllBase))
|
||||
|
||||
@@ -143,7 +149,6 @@ class ModDump(interfaces.plugins.PluginInterface):
|
||||
def run(self):
|
||||
return renderers.TreeGrid([("Base", format_hints.Hex), ("Name", str), ("Result", str)],
|
||||
self._generator(
|
||||
modules.Modules.list_modules(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'])))
|
||||
modules.Modules.list_modules(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'])))
|
||||
|
||||
@@ -18,8 +18,9 @@ class ModScan(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -19,8 +19,9 @@ class Modules(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
|
||||
]
|
||||
|
||||
|
||||
@@ -18,8 +18,9 @@ class MutantScan(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -27,17 +27,22 @@ class ProcDump(interfaces_plugins.PluginInterface):
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.IntRequirement(
|
||||
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
|
||||
requirements.IntRequirement(name = 'pid',
|
||||
description = "Process ID to include (all other processes are excluded)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _generator(self, procs):
|
||||
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(
|
||||
self.context, self.config_path, "windows", "pe", class_types = pe.class_types)
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
|
||||
self.config_path,
|
||||
"windows",
|
||||
"pe",
|
||||
class_types = pe.class_types)
|
||||
|
||||
for proc in procs:
|
||||
process_name = utility.array_to_string(proc.ImageFileName)
|
||||
@@ -45,15 +50,13 @@ class ProcDump(interfaces_plugins.PluginInterface):
|
||||
proc_layer_name = proc.add_process_layer()
|
||||
|
||||
try:
|
||||
peb = self._context.object(
|
||||
self.config["nt_symbols"] + constants.BANG + "_PEB",
|
||||
layer_name = proc_layer_name,
|
||||
offset = proc.Peb)
|
||||
peb = self._context.object(self.config["nt_symbols"] + constants.BANG + "_PEB",
|
||||
layer_name = proc_layer_name,
|
||||
offset = proc.Peb)
|
||||
|
||||
dos_header = self.context.object(
|
||||
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = peb.ImageBaseAddress,
|
||||
layer_name = proc_layer_name)
|
||||
dos_header = self.context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = peb.ImageBaseAddress,
|
||||
layer_name = proc_layer_name)
|
||||
|
||||
filedata = interfaces_plugins.FileInterface("pid.{0}.{1:#x}.dmp".format(
|
||||
proc.UniqueProcessId, peb.ImageBaseAddress))
|
||||
@@ -81,8 +84,7 @@ class ProcDump(interfaces_plugins.PluginInterface):
|
||||
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Result", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -22,17 +22,18 @@ class PsList(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
# TODO: Convert this to a ListRequirement so that people can filter on sets of pids
|
||||
requirements.BooleanRequirement(
|
||||
name = 'physical',
|
||||
description = 'Display physical offsets instead of virtual',
|
||||
default = cls.PHYSICAL_DEFAULT,
|
||||
optional = True),
|
||||
requirements.IntRequirement(
|
||||
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
|
||||
requirements.BooleanRequirement(name = 'physical',
|
||||
description = 'Display physical offsets instead of virtual',
|
||||
default = cls.PHYSICAL_DEFAULT,
|
||||
optional = True),
|
||||
requirements.IntRequirement(name = 'pid',
|
||||
description = "Process ID to include (all other processes are excluded)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
@classmethod
|
||||
@@ -124,11 +125,10 @@ class PsList(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
if not isinstance(memory, layers.intel.Intel):
|
||||
raise TypeError("Primary layer is not an intel layer")
|
||||
|
||||
for proc in self.list_processes(
|
||||
self.context,
|
||||
self.config['primary'],
|
||||
self.config['nt_symbols'],
|
||||
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
|
||||
for proc in self.list_processes(self.context,
|
||||
self.config['primary'],
|
||||
self.config['nt_symbols'],
|
||||
filter_func = self.create_pid_filter([self.config.get('pid', None)])):
|
||||
|
||||
if not self.config.get('physical', self.PHYSICAL_DEFAULT):
|
||||
offset = proc.vol.offset
|
||||
|
||||
@@ -19,8 +19,9 @@ class PsScan(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -21,19 +21,21 @@ class HiveList(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.StringRequirement(
|
||||
name = 'filter', description = "String to filter hive names returned", optional = True, default = None)
|
||||
requirements.StringRequirement(name = 'filter',
|
||||
description = "String to filter hive names returned",
|
||||
optional = True,
|
||||
default = None)
|
||||
]
|
||||
|
||||
def _generator(self) -> Iterator[Tuple[int, Tuple[int, str]]]:
|
||||
for hive in self.list_hive_objects(
|
||||
context = self.context,
|
||||
layer_name = self.config["primary"],
|
||||
symbol_table = self.config["nt_symbols"],
|
||||
filter_string = self.config.get('filter', None)):
|
||||
for hive in self.list_hive_objects(context = self.context,
|
||||
layer_name = self.config["primary"],
|
||||
symbol_table = self.config["nt_symbols"],
|
||||
filter_string = self.config.get('filter', None)):
|
||||
|
||||
yield (0, (format_hints.Hex(hive.vol.offset), hive.get_name() or ""))
|
||||
|
||||
@@ -69,12 +71,11 @@ class HiveList(plugins.PluginInterface):
|
||||
|
||||
for hive_offset in hive_offsets:
|
||||
# Construct the hive
|
||||
reg_config_path = cls.make_subconfig(
|
||||
context = context,
|
||||
base_config_path = base_config_path,
|
||||
hive_offset = hive_offset,
|
||||
base_layer = layer_name,
|
||||
nt_symbols = symbol_table)
|
||||
reg_config_path = cls.make_subconfig(context = context,
|
||||
base_config_path = base_config_path,
|
||||
hive_offset = hive_offset,
|
||||
base_layer = layer_name,
|
||||
nt_symbols = symbol_table)
|
||||
|
||||
try:
|
||||
hive = registry.RegistryHive(context, reg_config_path, name = 'hive' + hex(hive_offset))
|
||||
|
||||
@@ -19,8 +19,9 @@ class HiveScan(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -24,15 +24,20 @@ class PrintKey(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'hivelist', plugin = hivelist.HiveList, version = (1, 0, 0)),
|
||||
requirements.IntRequirement(name = 'offset', description = "Hive Offset", default = None, optional = True),
|
||||
requirements.StringRequirement(
|
||||
name = 'key', description = "Key to start from", default = None, optional = True),
|
||||
requirements.BooleanRequirement(
|
||||
name = 'recurse', description = 'Recurses through keys', default = False, optional = True)
|
||||
requirements.StringRequirement(name = 'key',
|
||||
description = "Key to start from",
|
||||
default = None,
|
||||
optional = True),
|
||||
requirements.BooleanRequirement(name = 'recurse',
|
||||
description = 'Recurses through keys',
|
||||
default = False,
|
||||
optional = True)
|
||||
]
|
||||
|
||||
@classmethod
|
||||
@@ -134,12 +139,11 @@ class PrintKey(interfaces.plugins.PluginInterface):
|
||||
key: str = None,
|
||||
recurse: bool = False):
|
||||
|
||||
for hive in hivelist.HiveList.list_hives(
|
||||
self.context,
|
||||
self.config_path,
|
||||
layer_name = layer_name,
|
||||
symbol_table = symbol_table,
|
||||
hive_offsets = hive_offsets):
|
||||
for hive in hivelist.HiveList.list_hives(self.context,
|
||||
self.config_path,
|
||||
layer_name = layer_name,
|
||||
symbol_table = symbol_table,
|
||||
hive_offsets = hive_offsets):
|
||||
|
||||
try:
|
||||
# Walk it
|
||||
@@ -164,12 +168,10 @@ class PrintKey(interfaces.plugins.PluginInterface):
|
||||
def run(self):
|
||||
offset = self.config.get('offset', None)
|
||||
|
||||
return TreeGrid(
|
||||
columns = [('Last Write Time', datetime.datetime), ('Hive Offset', format_hints.Hex), ('Type', str),
|
||||
('Key', str), ('Name', str), ('Data', str), ('Volatile', bool)],
|
||||
generator = self._registry_walker(
|
||||
self.config['primary'],
|
||||
self.config['nt_symbols'],
|
||||
hive_offsets = None if offset is None else [offset],
|
||||
key = self.config.get('key', None),
|
||||
recurse = self.config.get('recurse', None)))
|
||||
return TreeGrid(columns = [('Last Write Time', datetime.datetime), ('Hive Offset', format_hints.Hex),
|
||||
('Type', str), ('Key', str), ('Name', str), ('Data', str), ('Volatile', bool)],
|
||||
generator = self._registry_walker(self.config['primary'],
|
||||
self.config['nt_symbols'],
|
||||
hive_offsets = None if offset is None else [offset],
|
||||
key = self.config.get('key', None),
|
||||
recurse = self.config.get('recurse', None)))
|
||||
|
||||
@@ -36,8 +36,9 @@ class UserAssist(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.IntRequirement(name = 'offset', description = "Hive Offset", default = None, optional = True),
|
||||
requirements.PluginRequirement(name = 'hivelist', plugin = hivelist.HiveList, version = (1, 0, 0))
|
||||
@@ -130,8 +131,8 @@ class UserAssist(interfaces.plugins.PluginInterface):
|
||||
|
||||
self._determine_userassist_type()
|
||||
|
||||
userassist_node_path = hive.get_key(
|
||||
"software\\microsoft\\windows\\currentversion\\explorer\\userassist", return_list = True)
|
||||
userassist_node_path = hive.get_key("software\\microsoft\\windows\\currentversion\\explorer\\userassist",
|
||||
return_list = True)
|
||||
|
||||
if not userassist_node_path:
|
||||
vollog.warning("list_userassist did not find a valid node_path (or None)")
|
||||
@@ -215,13 +216,12 @@ class UserAssist(interfaces.plugins.PluginInterface):
|
||||
hive_offsets = [self.config.get('offset', None)]
|
||||
|
||||
# get all the user hive offsets or use the one specified
|
||||
for hive in hivelist.HiveList.list_hives(
|
||||
context = self.context,
|
||||
base_config_path = self.config_path,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_string = 'ntuser.dat',
|
||||
hive_offsets = hive_offsets):
|
||||
for hive in hivelist.HiveList.list_hives(context = self.context,
|
||||
base_config_path = self.config_path,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_string = 'ntuser.dat',
|
||||
hive_offsets = hive_offsets):
|
||||
try:
|
||||
yield from self.list_userassist(hive)
|
||||
continue
|
||||
|
||||
@@ -24,8 +24,9 @@ class SSDT(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'modules', plugin = modules.Modules, version = (1, 0, 0)),
|
||||
]
|
||||
@@ -61,8 +62,12 @@ class SSDT(plugins.PluginInterface):
|
||||
if module_name in windows_constants.KERNEL_MODULE_NAMES:
|
||||
symbol_table_name = symbol_table
|
||||
|
||||
context_module = contexts.SizedModule(
|
||||
context, module_name, layer_name, mod.DllBase, mod.SizeOfImage, symbol_table_name = symbol_table_name)
|
||||
context_module = contexts.SizedModule(context,
|
||||
module_name,
|
||||
layer_name,
|
||||
mod.DllBase,
|
||||
mod.SizeOfImage,
|
||||
symbol_table_name = symbol_table_name)
|
||||
|
||||
context_modules.append(context_module)
|
||||
|
||||
@@ -102,11 +107,10 @@ class SSDT(plugins.PluginInterface):
|
||||
|
||||
find_address = passthrough
|
||||
|
||||
functions = ntkrnlmp.object(
|
||||
object_type = "array",
|
||||
offset = service_table_address,
|
||||
subtype = ntkrnlmp.get_type(array_subtype),
|
||||
count = service_limit)
|
||||
functions = ntkrnlmp.object(object_type = "array",
|
||||
offset = service_table_address,
|
||||
subtype = ntkrnlmp.get_type(array_subtype),
|
||||
count = service_limit)
|
||||
|
||||
for idx, function_obj in enumerate(functions):
|
||||
|
||||
|
||||
@@ -21,8 +21,9 @@ class Strings(interfaces.plugins.PluginInterface):
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.URIRequirement(name = "strings_file", description = "Strings file")
|
||||
]
|
||||
|
||||
@@ -21,33 +21,34 @@ class SvcScan(interfaces.plugins.PluginInterface):
|
||||
|
||||
_version = (1, 0, 0)
|
||||
|
||||
is_vista_or_later = poolscanner.os_distinguisher(
|
||||
version_check = lambda x: x >= (6, 0), fallback_checks = [("KdCopyDataBlock", None, True)])
|
||||
is_vista_or_later = poolscanner.os_distinguisher(version_check = lambda x: x >= (6, 0),
|
||||
fallback_checks = [("KdCopyDataBlock", None, True)])
|
||||
|
||||
is_windows_xp = poolscanner.os_distinguisher(
|
||||
version_check = lambda x: (5, 1) <= x < (5, 2),
|
||||
fallback_checks = [("KdCopyDataBlock", None, False), ("_HANDLE_TABLE", "HandleCount", True)])
|
||||
is_windows_xp = poolscanner.os_distinguisher(version_check = lambda x: (5, 1) <= x < (5, 2),
|
||||
fallback_checks = [("KdCopyDataBlock", None, False),
|
||||
("_HANDLE_TABLE", "HandleCount", True)])
|
||||
|
||||
is_xp_or_2003 = poolscanner.os_distinguisher(
|
||||
version_check = lambda x: (5, 1) <= x < (6, 0),
|
||||
fallback_checks = [("KdCopyDataBlock", None, False), ("_HANDLE_TABLE", "HandleCount", True)])
|
||||
is_xp_or_2003 = poolscanner.os_distinguisher(version_check = lambda x: (5, 1) <= x < (6, 0),
|
||||
fallback_checks = [("KdCopyDataBlock", None, False),
|
||||
("_HANDLE_TABLE", "HandleCount", True)])
|
||||
|
||||
is_win10_up_to_15063 = poolscanner.os_distinguisher(
|
||||
version_check = lambda x: (10, 0) <= x < (10, 0, 16299),
|
||||
fallback_checks = [("ObHeaderCookie", None, True), ("_HANDLE_TABLE", "HandleCount", False),
|
||||
("ObHeaderCookie", None, True)])
|
||||
is_win10_up_to_15063 = poolscanner.os_distinguisher(version_check = lambda x: (10, 0) <= x < (10, 0, 16299),
|
||||
fallback_checks = [("ObHeaderCookie", None, True),
|
||||
("_HANDLE_TABLE", "HandleCount", False),
|
||||
("ObHeaderCookie", None, True)])
|
||||
|
||||
is_win10_16299_or_later = poolscanner.os_distinguisher(
|
||||
version_check = lambda x: x >= (10, 0, 16299),
|
||||
fallback_checks = [("ObHeaderCookie", None, True), ("_HANDLE_TABLE", "HandleCount", False),
|
||||
("ObHeaderCookie", None, True)])
|
||||
is_win10_16299_or_later = poolscanner.os_distinguisher(version_check = lambda x: x >= (10, 0, 16299),
|
||||
fallback_checks = [("ObHeaderCookie", None, True),
|
||||
("_HANDLE_TABLE", "HandleCount", False),
|
||||
("ObHeaderCookie", None, True)])
|
||||
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
requirements.PluginRequirement(name = 'poolscanner', plugin = poolscanner.PoolScanner, version = (1, 0, 0)),
|
||||
@@ -82,8 +83,8 @@ class SvcScan(interfaces.plugins.PluginInterface):
|
||||
symbol_filename = "services-xp-2003-x64"
|
||||
elif poolscanner.PoolScanner.is_windows_8_or_later(context = context, symbol_table = symbol_table) and is_64bit:
|
||||
symbol_filename = "services-win8-x64"
|
||||
elif poolscanner.PoolScanner.is_windows_8_or_later(
|
||||
context = context, symbol_table = symbol_table) and not is_64bit:
|
||||
elif poolscanner.PoolScanner.is_windows_8_or_later(context = context,
|
||||
symbol_table = symbol_table) and not is_64bit:
|
||||
symbol_filename = "services-win8-x86"
|
||||
elif SvcScan.is_win10_up_to_15063(context = context, symbol_table = symbol_table) and is_64bit:
|
||||
symbol_filename = "services-win10-15063-x64"
|
||||
@@ -100,13 +101,12 @@ class SvcScan(interfaces.plugins.PluginInterface):
|
||||
else:
|
||||
raise NotImplementedError("This version of Windows is not supported!")
|
||||
|
||||
return intermed.IntermediateSymbolTable.create(
|
||||
context,
|
||||
config_path,
|
||||
"windows",
|
||||
symbol_filename,
|
||||
class_types = services.class_types,
|
||||
native_types = native_types)
|
||||
return intermed.IntermediateSymbolTable.create(context,
|
||||
config_path,
|
||||
"windows",
|
||||
symbol_filename,
|
||||
class_types = services.class_types,
|
||||
native_types = native_types)
|
||||
|
||||
def _generator(self):
|
||||
|
||||
@@ -126,35 +126,31 @@ class SvcScan(interfaces.plugins.PluginInterface):
|
||||
|
||||
seen = []
|
||||
|
||||
for task in pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func):
|
||||
for task in pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func):
|
||||
|
||||
proc_layer_name = task.add_process_layer()
|
||||
layer = self.context.layers[proc_layer_name]
|
||||
|
||||
for offset in layer.scan(
|
||||
context = self.context,
|
||||
scanner = scanners.BytesScanner(needle = service_tag),
|
||||
sections = vadyarascan.VadYaraScan.get_vad_maps(task)):
|
||||
for offset in layer.scan(context = self.context,
|
||||
scanner = scanners.BytesScanner(needle = service_tag),
|
||||
sections = vadyarascan.VadYaraScan.get_vad_maps(task)):
|
||||
|
||||
if not is_vista_or_later:
|
||||
service_record = self.context.object(
|
||||
service_table_name + constants.BANG + "_SERVICE_RECORD",
|
||||
offset = offset - relative_tag_offset,
|
||||
layer_name = proc_layer_name)
|
||||
service_record = self.context.object(service_table_name + constants.BANG + "_SERVICE_RECORD",
|
||||
offset = offset - relative_tag_offset,
|
||||
layer_name = proc_layer_name)
|
||||
|
||||
if not service_record.is_valid():
|
||||
continue
|
||||
|
||||
yield (0, self.get_record_tuple(service_record))
|
||||
else:
|
||||
service_header = self.context.object(
|
||||
service_table_name + constants.BANG + "_SERVICE_HEADER",
|
||||
offset = offset,
|
||||
layer_name = proc_layer_name)
|
||||
service_header = self.context.object(service_table_name + constants.BANG + "_SERVICE_HEADER",
|
||||
offset = offset,
|
||||
layer_name = proc_layer_name)
|
||||
|
||||
if not service_header.is_valid():
|
||||
continue
|
||||
|
||||
@@ -18,8 +18,9 @@ class SymlinkScan(plugins.PluginInterface, timeliner.TimeLinerInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
|
||||
@@ -79,8 +79,7 @@ class VadDump(interfaces_plugins.PluginInterface):
|
||||
|
||||
return renderers.TreeGrid([("PID", int), ("Process", str), ("Result", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -126,8 +126,7 @@ class VadInfo(interfaces.plugins.PluginInterface):
|
||||
("Protection", str), ("CommitCharge", int), ("PrivateMemory", int),
|
||||
("Parent", format_hints.Hex), ("File", str)],
|
||||
self._generator(
|
||||
pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func)))
|
||||
|
||||
@@ -26,22 +26,26 @@ class VadYaraScan(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = "Memory layer for the kernel", architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = "Memory layer for the kernel",
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
requirements.BooleanRequirement(
|
||||
name = "wide", description = "Match wide (unicode) strings", default = False, optional = True),
|
||||
requirements.StringRequirement(
|
||||
name = "yara_rules", description = "Yara rules (as a string)", optional = True),
|
||||
requirements.BooleanRequirement(name = "wide",
|
||||
description = "Match wide (unicode) strings",
|
||||
default = False,
|
||||
optional = True),
|
||||
requirements.StringRequirement(name = "yara_rules",
|
||||
description = "Yara rules (as a string)",
|
||||
optional = True),
|
||||
requirements.URIRequirement(name = "yara_file", description = "Yara rules (as a file)", optional = True),
|
||||
requirements.IntRequirement(
|
||||
name = "max_size",
|
||||
default = 0x40000000,
|
||||
description = "Set the maximum size (default is 1GB)",
|
||||
optional = True),
|
||||
requirements.IntRequirement(name = "max_size",
|
||||
default = 0x40000000,
|
||||
description = "Set the maximum size (default is 1GB)",
|
||||
optional = True),
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
requirements.IntRequirement(
|
||||
name = 'pid', description = "Process ID to include (all other processes are excluded)", optional = True)
|
||||
requirements.IntRequirement(name = 'pid',
|
||||
description = "Process ID to include (all other processes are excluded)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
@@ -64,15 +68,13 @@ class VadYaraScan(interfaces.plugins.PluginInterface):
|
||||
|
||||
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
|
||||
|
||||
for task in pslist.PsList.list_processes(
|
||||
context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func):
|
||||
for offset, name in layer.scan(
|
||||
context = self.context,
|
||||
scanner = yarascan.YaraScanner(rules = rules),
|
||||
sections = self.get_vad_maps(task)):
|
||||
for task in pslist.PsList.list_processes(context = self.context,
|
||||
layer_name = self.config['primary'],
|
||||
symbol_table = self.config['nt_symbols'],
|
||||
filter_func = filter_func):
|
||||
for offset, name in layer.scan(context = self.context,
|
||||
scanner = yarascan.YaraScanner(rules = rules),
|
||||
sections = self.get_vad_maps(task)):
|
||||
yield format_hints.Hex(offset), name
|
||||
|
||||
@staticmethod
|
||||
|
||||
@@ -34,8 +34,9 @@ class VerInfo(interfaces_plugins.PluginInterface):
|
||||
## TODO: and we don't want any CLI options from pslist, modules, or moddump
|
||||
return [
|
||||
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (1, 0, 0)),
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols"),
|
||||
]
|
||||
|
||||
@@ -56,8 +57,9 @@ class VerInfo(interfaces_plugins.PluginInterface):
|
||||
|
||||
pe_data = io.BytesIO()
|
||||
|
||||
dos_header = context.object(
|
||||
pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER", offset = base_address, layer_name = layer_name)
|
||||
dos_header = context.object(pe_table_name + constants.BANG + "_IMAGE_DOS_HEADER",
|
||||
offset = base_address,
|
||||
layer_name = layer_name)
|
||||
|
||||
for offset, data in dos_header.reconstruct():
|
||||
pe_data.seek(offset)
|
||||
@@ -94,8 +96,11 @@ class VerInfo(interfaces_plugins.PluginInterface):
|
||||
session_layers: <generator> of layers in the session to be checked
|
||||
"""
|
||||
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(
|
||||
self.context, self.config_path, "windows", "pe", class_types = extensions.pe.class_types)
|
||||
pe_table_name = intermed.IntermediateSymbolTable.create(self.context,
|
||||
self.config_path,
|
||||
"windows",
|
||||
"pe",
|
||||
class_types = extensions.pe.class_types)
|
||||
|
||||
for mod in mods:
|
||||
try:
|
||||
@@ -136,9 +141,10 @@ class VerInfo(interfaces_plugins.PluginInterface):
|
||||
(major, minor, product, build) = [renderers.UnreadableValue()] * 4
|
||||
|
||||
yield (0, (proc.UniqueProcessId,
|
||||
proc.ImageFileName.cast(
|
||||
"string", max_length = proc.ImageFileName.vol.count, errors = "replace"),
|
||||
format_hints.Hex(entry.DllBase), BaseDllName, major, minor, product, build))
|
||||
proc.ImageFileName.cast("string",
|
||||
max_length = proc.ImageFileName.vol.count,
|
||||
errors = "replace"), format_hints.Hex(entry.DllBase), BaseDllName,
|
||||
major, minor, product, build))
|
||||
|
||||
def run(self):
|
||||
procs = pslist.PsList.list_processes(self.context, self.config["primary"], self.config["nt_symbols"])
|
||||
|
||||
@@ -23,8 +23,9 @@ class VirtMap(interfaces.plugins.PluginInterface):
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
# Since we're calling the plugin, make sure we have the plugin's requirements
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = 'Memory layer for the kernel', architectures = ["Intel32", "Intel64"]),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = 'Memory layer for the kernel',
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.SymbolTableRequirement(name = "nt_symbols", description = "Windows kernel symbols")
|
||||
]
|
||||
|
||||
@@ -50,30 +51,32 @@ class VirtMap(interfaces.plugins.PluginInterface):
|
||||
|
||||
if module.has_symbol('MiVisibleState'):
|
||||
symbol = module.get_symbol('MiVisibleState')
|
||||
visible_state = module.object(
|
||||
object_type = 'pointer', offset = symbol.address,
|
||||
subtype = module.get_type('_MI_VISIBLE_STATE')).dereference()
|
||||
visible_state = module.object(object_type = 'pointer',
|
||||
offset = symbol.address,
|
||||
subtype = module.get_type('_MI_VISIBLE_STATE')).dereference()
|
||||
if hasattr(visible_state, 'SystemVaRegions'):
|
||||
for i in range(visible_state.SystemVaRegions.count):
|
||||
lookup = system_va_type.lookup(i)
|
||||
region_range = result.get(lookup, [])
|
||||
region_range.append((visible_state.SystemVaRegions[i].BaseAddress,
|
||||
visible_state.SystemVaRegions[i].NumberOfBytes))
|
||||
region_range.append(
|
||||
(visible_state.SystemVaRegions[i].BaseAddress, visible_state.SystemVaRegions[i].NumberOfBytes))
|
||||
result[lookup] = region_range
|
||||
elif hasattr(visible_state, 'SystemVaType'):
|
||||
system_range_start = module.object(
|
||||
object_type = "pointer", offset = module.get_symbol("MmSystemRangeStart").address)
|
||||
system_range_start = module.object(object_type = "pointer",
|
||||
offset = module.get_symbol("MmSystemRangeStart").address)
|
||||
result = cls._enumerate_system_va_type(large_page_size, system_range_start, module,
|
||||
visible_state.SystemVaType)
|
||||
else:
|
||||
raise exceptions.SymbolError("Required structures not found")
|
||||
elif module.has_symbol('MiSystemVaType'):
|
||||
system_range_start = module.object(
|
||||
object_type = "pointer", offset = module.get_symbol("MmSystemRangeStart").address)
|
||||
system_range_start = module.object(object_type = "pointer",
|
||||
offset = module.get_symbol("MmSystemRangeStart").address)
|
||||
symbol = module.get_symbol('MiSystemVaType')
|
||||
array_count = (0xFFFFFFFF + 1 - system_range_start) // large_page_size
|
||||
type_array = module.object(
|
||||
object_type = 'array', offset = symbol.address, count = array_count, subtype = module.get_type('char'))
|
||||
type_array = module.object(object_type = 'array',
|
||||
offset = symbol.address,
|
||||
count = array_count,
|
||||
subtype = module.get_type('char'))
|
||||
|
||||
result = cls._enumerate_system_va_type(large_page_size, system_range_start, module, type_array)
|
||||
else:
|
||||
@@ -114,8 +117,9 @@ class VirtMap(interfaces.plugins.PluginInterface):
|
||||
|
||||
def run(self):
|
||||
layer = self.context.layers[self.config['primary']]
|
||||
module = self.context.module(
|
||||
self.config['nt_symbols'], layer_name = layer.name, offset = layer.config['kernel_virtual_offset'])
|
||||
module = self.context.module(self.config['nt_symbols'],
|
||||
layer_name = layer.name,
|
||||
offset = layer.config['kernel_virtual_offset'])
|
||||
|
||||
return renderers.TreeGrid([("Region", str), ("Start offset", format_hints.Hex),
|
||||
("End offset", format_hints.Hex)],
|
||||
|
||||
@@ -40,27 +40,33 @@ class YaraScan(plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
|
||||
return [
|
||||
requirements.TranslationLayerRequirement(
|
||||
name = 'primary', description = "Memory layer for the kernel", architectures = ["Intel32", "Intel64"]),
|
||||
requirements.BooleanRequirement(
|
||||
name = "all", description = "Scan both process and kernel memory", default = False, optional = True),
|
||||
requirements.BooleanRequirement(
|
||||
name = "insensitive",
|
||||
description = "Makes the search case insensitive",
|
||||
default = False,
|
||||
optional = True),
|
||||
requirements.BooleanRequirement(
|
||||
name = "kernel", description = "Scan kernel modules", default = False, optional = True),
|
||||
requirements.BooleanRequirement(
|
||||
name = "wide", description = "Match wide (unicode) strings", default = False, optional = True),
|
||||
requirements.StringRequirement(
|
||||
name = "yara_rules", description = "Yara rules (as a string)", optional = True),
|
||||
requirements.TranslationLayerRequirement(name = 'primary',
|
||||
description = "Memory layer for the kernel",
|
||||
architectures = ["Intel32", "Intel64"]),
|
||||
requirements.BooleanRequirement(name = "all",
|
||||
description = "Scan both process and kernel memory",
|
||||
default = False,
|
||||
optional = True),
|
||||
requirements.BooleanRequirement(name = "insensitive",
|
||||
description = "Makes the search case insensitive",
|
||||
default = False,
|
||||
optional = True),
|
||||
requirements.BooleanRequirement(name = "kernel",
|
||||
description = "Scan kernel modules",
|
||||
default = False,
|
||||
optional = True),
|
||||
requirements.BooleanRequirement(name = "wide",
|
||||
description = "Match wide (unicode) strings",
|
||||
default = False,
|
||||
optional = True),
|
||||
requirements.StringRequirement(name = "yara_rules",
|
||||
description = "Yara rules (as a string)",
|
||||
optional = True),
|
||||
requirements.URIRequirement(name = "yara_file", description = "Yara rules (as a file)", optional = True),
|
||||
requirements.IntRequirement(
|
||||
name = "max_size",
|
||||
default = 0x40000000,
|
||||
description = "Set the maximum size (default is 1GB)",
|
||||
optional = True)
|
||||
requirements.IntRequirement(name = "max_size",
|
||||
default = 0x40000000,
|
||||
description = "Set the maximum size (default is 1GB)",
|
||||
optional = True)
|
||||
]
|
||||
|
||||
def _generator(self):
|
||||
|
||||
Reference in New Issue
Block a user