mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-09 19:27:39 +02:00
minor improvments
This commit is contained in:
@@ -115,7 +115,15 @@ class ObjectInterface(metaclass = abc.ABCMeta):
|
||||
mask = context.layers[object_info.layer_name].address_mask
|
||||
normalized_offset = object_info.offset & mask
|
||||
|
||||
self._vol = collections.ChainMap({}, {'type_name': type_name, 'offset': normalized_offset}, object_info, kwargs)
|
||||
vol_info_dict = {'type_name': type_name, 'offset': normalized_offset}
|
||||
if constants.BANG in type_name:
|
||||
table_name, struct_name = type_name.split(constants.BANG)
|
||||
vol_info_dict["table_name"] = table_name
|
||||
vol_info_dict["short_name"] = struct_name
|
||||
else:
|
||||
vol_info_dict["short_name"] = type_name
|
||||
|
||||
self._vol = collections.ChainMap({}, vol_info_dict, object_info, kwargs)
|
||||
self._context = context
|
||||
|
||||
def __getattr__(self, attr: str) -> Any:
|
||||
@@ -142,7 +150,7 @@ class ObjectInterface(metaclass = abc.ABCMeta):
|
||||
"""
|
||||
if constants.BANG not in self.vol.type_name:
|
||||
raise ValueError(f"Unable to determine table for symbol: {self.vol.type_name}")
|
||||
table_name = self.vol.type_name[:self.vol.type_name.index(constants.BANG)]
|
||||
table_name = self.vol.table_name
|
||||
if table_name not in self._context.symbol_space:
|
||||
raise KeyError(f"Symbol table not found in context's symbol_space for symbol: {self.vol.type_name}")
|
||||
return table_name
|
||||
@@ -156,7 +164,7 @@ class ObjectInterface(metaclass = abc.ABCMeta):
|
||||
"""
|
||||
# TODO: Carefully consider the implications of casting and how it should work
|
||||
if constants.BANG not in new_type_name:
|
||||
symbol_table = self.vol['type_name'].split(constants.BANG)[0]
|
||||
symbol_table = self.get_symbol_table_name()
|
||||
new_type_name = symbol_table + constants.BANG + new_type_name
|
||||
object_template = self._context.symbol_space.get_type(new_type_name)
|
||||
object_template = object_template.clone()
|
||||
@@ -169,6 +177,11 @@ class ObjectInterface(metaclass = abc.ABCMeta):
|
||||
size = object_template.size)
|
||||
return object_template(context = self._context, object_info = object_info)
|
||||
|
||||
def at_layer(self, new_layer_name) -> 'ObjectInterface':
|
||||
"""Returns the same object casted at a different layer.
|
||||
"""
|
||||
return self._context.object(self.vol.type_name, offset=self.vol.offset, layer_name=new_layer_name)
|
||||
|
||||
def has_member(self, member_name: str) -> bool:
|
||||
"""Returns whether the object would contain a member called
|
||||
member_name.
|
||||
|
||||
@@ -167,6 +167,20 @@ class BaseSymbolTableInterface:
|
||||
"""
|
||||
raise NotImplementedError("Abstract method set_type_class not implemented yet.")
|
||||
|
||||
def try_set_type_class(self, name: str, clazz: Type[objects.ObjectInterface]) -> bool:
|
||||
"""Calls the set_type_class function but does not throw an exception.
|
||||
Returns whether setting the type class was successfull.
|
||||
Args:
|
||||
name: The name of the type to override the class for
|
||||
clazz: The actual class to override for the provided type name
|
||||
"""
|
||||
try:
|
||||
self.set_type_class(name, clazz)
|
||||
|
||||
return True
|
||||
except ValueError:
|
||||
return False
|
||||
|
||||
def get_type_class(self, name: str) -> Type[objects.ObjectInterface]:
|
||||
"""Returns the class associated with a Symbol type."""
|
||||
raise NotImplementedError("Abstract method get_type_class not implemented yet.")
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
|
||||
from volatility3.framework.symbols import intermed
|
||||
from volatility3.framework.symbols.windows import extensions
|
||||
from volatility3.framework.symbols.windows.extensions import registry, pool
|
||||
from volatility3.framework.symbols.windows.extensions import registry, pool, pe
|
||||
|
||||
|
||||
class WindowsKernelIntermedSymbols(intermed.IntermediateSymbolTable):
|
||||
@@ -38,6 +38,11 @@ class WindowsKernelIntermedSymbols(intermed.IntermediateSymbolTable):
|
||||
self.set_type_class('_SHARED_CACHE_MAP', extensions.SHARED_CACHE_MAP)
|
||||
self.set_type_class('_VACB', extensions.VACB)
|
||||
self.set_type_class('_POOL_TRACKER_BIG_PAGES', pool.POOL_TRACKER_BIG_PAGES)
|
||||
self.set_type_class('_IMAGE_DOS_HEADER', pe.IMAGE_DOS_HEADER)
|
||||
self.set_type_class('_IMAGE_NT_HEADERS', pe.IMAGE_NT_HEADERS)
|
||||
|
||||
# Might not exist in 32-bit operating systems.
|
||||
self.try_set_type_class('_IMAGE_NT_HEADERS64', pe.IMAGE_NT_HEADERS)
|
||||
|
||||
# This doesn't exist in very specific versions of windows
|
||||
try:
|
||||
@@ -49,19 +54,11 @@ class WindowsKernelIntermedSymbols(intermed.IntermediateSymbolTable):
|
||||
pass
|
||||
|
||||
# these don't exist in windows XP
|
||||
try:
|
||||
self.set_type_class('_MMADDRESS_NODE', extensions.MMVAD_SHORT)
|
||||
except ValueError:
|
||||
pass
|
||||
|
||||
self.try_set_type_class('_MMADDRESS_NODE', extensions.MMVAD_SHORT)
|
||||
|
||||
# these were introduced starting in windows 8
|
||||
try:
|
||||
self.set_type_class('_MM_AVL_NODE', extensions.MMVAD_SHORT)
|
||||
except ValueError:
|
||||
pass
|
||||
|
||||
self.try_set_type_class('_MM_AVL_NODE', extensions.MMVAD_SHORT)
|
||||
|
||||
# these were introduced starting in windows 7
|
||||
try:
|
||||
self.set_type_class('_RTL_BALANCED_NODE', extensions.MMVAD_SHORT)
|
||||
except ValueError:
|
||||
pass
|
||||
self.try_set_type_class('_RTL_BALANCED_NODE', extensions.MMVAD_SHORT)
|
||||
|
||||
@@ -574,13 +574,9 @@ class EPROCESS(generic.GenericIntelProcess, pool.ExecutiveObject):
|
||||
proc_layer = self._context.layers[proc_layer_name]
|
||||
if not proc_layer.is_valid(self.Peb):
|
||||
raise exceptions.InvalidAddressException(proc_layer_name, self.Peb,
|
||||
f"Invalid address at {self.Peb:0x}")
|
||||
f"Invalid Peb address at {self.Peb:0x}")
|
||||
|
||||
sym_table = self.vol.type_name.split(constants.BANG)[0]
|
||||
peb = self._context.object(f"{sym_table}{constants.BANG}_PEB",
|
||||
layer_name = proc_layer_name,
|
||||
offset = self.Peb)
|
||||
return peb
|
||||
return self.at_layer(proc_layer_name).Peb
|
||||
|
||||
def load_order_modules(self) -> Iterable[interfaces.objects.ObjectInterface]:
|
||||
"""Generator for DLLs in the order that they were loaded."""
|
||||
|
||||
Reference in New Issue
Block a user