Mac: Consolidate methods of listing processes

This also updates all other plugins that rely on process listing
and theoretically allows them to choose their preferred method of
process listing.  At the moment, the default (first in the method list)
is chosen.  An optional pslist_method StringRequirement can be added to
each plugin, but using the list in the requirements could break if the
pslist plugin is too old (ie, using the list would happen before the
PluginRequirement gets checked).

If this is a feature we want, it should be easy to add to all but
netstat, which does not parameterize the list of processes.
This commit is contained in:
Mike Auty
2020-07-18 16:38:49 +01:00
committed by ikelos
parent 0ccb1f82e6
commit 7673dd8d2d
10 changed files with 214 additions and 210 deletions
@@ -6,7 +6,7 @@ from volatility.framework import renderers, interfaces
from volatility.framework.configuration import requirements
from volatility.framework.objects import utility
from volatility.framework.renderers import format_hints
from volatility.plugins.mac import tasks
from volatility.plugins.mac import pslist
class Maps(interfaces.plugins.PluginInterface):
@@ -19,7 +19,7 @@ class Maps(interfaces.plugins.PluginInterface):
description = 'Memory layer for the kernel',
architectures = ["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(name = "darwin", description = "Linux kernel symbols"),
requirements.PluginRequirement(name = 'tasks', plugin = tasks.Tasks, version = (1, 0, 0))
requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (2, 0, 0))
]
def _generator(self, tasks):
@@ -36,12 +36,13 @@ class Maps(interfaces.plugins.PluginInterface):
format_hints.Hex(vma.links.end), vma.get_perms(), path))
def run(self):
filter_func = tasks.Tasks.create_pid_filter([self.config.get('pid', None)])
filter_func = pslist.PsList.create_pid_filter([self.config.get('pid', None)])
list_tasks = pslist.PsList.get_list_tasks(self.config.get('pslist_method', pslist.PsList.pslist_methods[0]))
return renderers.TreeGrid([("PID", int), ("Process", str), ("Start", format_hints.Hex),
("End", format_hints.Hex), ("Protection", str), ("Map Name", str)],
self._generator(
tasks.Tasks.list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))
list_tasks(self.context,
self.config['primary'],
self.config['darwin'],
filter_func = filter_func)))