fix merge conflicts

This commit is contained in:
Dave Lassalle
2025-03-27 08:25:34 -05:00
160 changed files with 5847 additions and 1037 deletions
+1 -1
View File
@@ -9,7 +9,7 @@ jobs:
steps:
- uses: actions/checkout@v4
- uses: astral-sh/ruff-action@v1
- uses: astral-sh/ruff-action@v3.2.1
with:
args: check
src: "."
+6 -2
View File
@@ -31,13 +31,17 @@ jobs:
gunzip linux-sample-1.bin.gz
curl -sLO "https://downloads.volatilityfoundation.org/volatility3/images/win-xp-laptop-2005-06-25.img.gz"
gunzip win-xp-laptop-2005-06-25.img.gz
curl -sLO "https://downloads.volatilityfoundation.org/volatility3/images/win-10_19041-2025_03.dmp.gz"
gunzip win-10_19041-2025_03.dmp.gz
cd -
- name: Download and Extract symbols
run: |
cd ./volatility3/symbols
curl -sLO https://downloads.volatilityfoundation.org/volatility3/symbols/linux.zip
curl -sLO https://downloads.volatilityfoundation.org/volatility3/symbols/symbols_win-10_19041-2025_03.zip
unzip linux.zip
unzip symbols_win-10_19041-2025_03.zip
cd -
- name: Testing...
@@ -47,8 +51,8 @@ jobs:
pytest ./test/plugins/linux/linux.py --volatility=volshell.py --image-dir=./test_images -k test_linux_volshell -v
# Volatility
pytest ./test/plugins/windows/windows.py --volatility=vol.py --image-dir=./test_images -k "test_windows and not test_windows_volshell" -v
pytest ./test/plugins/linux/linux.py --volatility=vol.py --image-dir=./test_images -k "test_linux and not test_linux_volshell" -v
pytest ./test/plugins/windows/windows.py --volatility=vol.py --image=./test_images/win-10_19041-2025_03.dmp -k "test_windows and not test_windows_volshell" -v --durations=0
pytest ./test/plugins/linux/linux.py --volatility=vol.py --image-dir=./test_images -k "test_linux and not test_linux_volshell" -v --durations=0
- name: Clean up post-test
run: |
+2 -2
View File
@@ -53,9 +53,9 @@ to be able to run properly. Any that are defined as optional need not necessari
description = "Process IDs to include (all other processes are excluded)",
optional = True
),
requirements.PluginRequirement(
requirements.VersionRequirement(
name = 'pslist',
plugin = pslist.PsList,
component = pslist.PsList,
version = (2, 0, 0)
),
]
+6
View File
@@ -1,4 +1,8 @@
from enum import Enum
from pathlib import Path
TESTS_ROOT_DIR = Path(__file__).parent
WINDOWS_TESTS_DATA_DIR = TESTS_ROOT_DIR / "plugins" / "windows" / "test_data"
class Sample:
@@ -9,6 +13,8 @@ class Sample:
class WindowsSamples(Enum):
WINDOWSXP_GENERIC = Sample("./test_images/win-xp-laptop-2005-06-25.img")
"""WindowsXP sample from early Volatility training."""
WINDOWS10_GENERIC = Sample("./test_images/win-10_19041-2025_03.dmp")
"""Windows10 CrashDump sample."""
class LinuxSamples(Enum):
+1 -1
View File
@@ -8,7 +8,7 @@ from test import test_volatility, LinuxSamples
class TestLinuxVolshell:
def test_linux_volshell(self, image, volatility, python):
out = test_volatility.basic_volshell_test(
image, volatility, python, globalargs=("-l",)
image, volatility, python, volshellargs=("-l",)
)
assert out.count(b"<task_struct") > 100
@@ -0,0 +1,32 @@
{
"GENERIC": [
"IRP_MJ_CREATE",
"IRP_MJ_CREATE_NAMED_PIPE",
"IRP_MJ_CLOSE",
"IRP_MJ_READ",
"IRP_MJ_WRITE",
"IRP_MJ_QUERY_INFORMATION",
"IRP_MJ_SET_INFORMATION",
"IRP_MJ_QUERY_EA",
"IRP_MJ_SET_EA",
"IRP_MJ_FLUSH_BUFFERS",
"IRP_MJ_QUERY_VOLUME_INFORMATION",
"IRP_MJ_SET_VOLUME_INFORMATION",
"IRP_MJ_DIRECTORY_CONTROL",
"IRP_MJ_FILE_SYSTEM_CONTROL",
"IRP_MJ_DEVICE_CONTROL",
"IRP_MJ_INTERNAL_DEVICE_CONTROL",
"IRP_MJ_SHUTDOWN",
"IRP_MJ_LOCK_CONTROL",
"IRP_MJ_CLEANUP",
"IRP_MJ_CREATE_MAILSLOT",
"IRP_MJ_QUERY_SECURITY",
"IRP_MJ_SET_SECURITY",
"IRP_MJ_POWER",
"IRP_MJ_SYSTEM_CONTROL",
"IRP_MJ_DEVICE_CHANGE",
"IRP_MJ_QUERY_QUOTA",
"IRP_MJ_SET_QUOTA",
"IRP_MJ_PNP"
]
}
@@ -0,0 +1,96 @@
{
"WINDOWS10_GENERIC": [
{
"Value": "0xf8043601f000",
"Variable": "Kernel Base"
},
{
"Value": "0x6d4000",
"Variable": "DTB"
},
{
"Value": "True",
"Variable": "Is64Bit"
},
{
"Value": "False",
"Variable": "IsPAE"
},
{
"Value": "0 WindowsIntel32e",
"Variable": "layer_name"
},
{
"Value": "1 WindowsCrashDump64Layer",
"Variable": "memory_layer"
},
{
"Value": "2 FileLayer",
"Variable": "base_layer"
},
{
"Value": "0xf80436c1fb20",
"Variable": "KdDebuggerDataBlock"
},
{
"Value": "19041.1.amd64fre.vb_release.1912",
"Variable": "NTBuildLab"
},
{
"Value": "0",
"Variable": "CSDVersion"
},
{
"Value": "0xf80436c2e420",
"Variable": "KdVersionBlock"
},
{
"Value": "15.19041",
"Variable": "Major/Minor"
},
{
"Value": "34404",
"Variable": "MachineType"
},
{
"Value": "1",
"Variable": "KeNumberProcessors"
},
{
"Value": "2025-03-06 17:59:20+00:00",
"Variable": "SystemTime"
},
{
"Value": "C:\\Windows",
"Variable": "NtSystemRoot"
},
{
"Value": "NtProductWinNt",
"Variable": "NtProductType"
},
{
"Value": "10",
"Variable": "NtMajorVersion"
},
{
"Value": "0",
"Variable": "NtMinorVersion"
},
{
"Value": "10",
"Variable": "PE MajorOperatingSystemVersion"
},
{
"Value": "0",
"Variable": "PE MinorOperatingSystemVersion"
},
{
"Value": "34404",
"Variable": "PE Machine"
},
{
"Value": "Tue Sep 26 06:53:33 2023",
"Variable": "PE TimeDateStamp"
}
]
}
@@ -0,0 +1,375 @@
{
"WINDOWS10_GENERIC": {
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\winlogon.exe",
"Cmd": null,
"CreateTime": "2025-03-06T17:49:34+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "winlogon.exe",
"Offset(V)": 145201769754752,
"PID": 3616,
"PPID": 3568,
"Path": null,
"SessionId": 2,
"Threads": 3,
"Wow64": false,
"__children": [
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\userinit.exe",
"Cmd": null,
"CreateTime": "2025-03-06T17:50:15+00:00",
"ExitTime": "2025-03-06T17:50:32+00:00",
"Handles": null,
"ImageFileName": "userinit.exe",
"Offset(V)": 145201786712256,
"PID": 4832,
"PPID": 3616,
"Path": null,
"SessionId": 2,
"Threads": 0,
"Wow64": false,
"__children": [
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\explorer.exe",
"Cmd": "C:\\Windows\\Explorer.EXE",
"CreateTime": "2025-03-06T17:50:17+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "explorer.exe",
"Offset(V)": 145201787191488,
"PID": 4912,
"PPID": 4832,
"Path": "C:\\Windows\\Explorer.EXE",
"SessionId": 2,
"Threads": 57,
"Wow64": false,
"__children": [
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\SecurityHealthSystray.exe",
"Cmd": "\"C:\\Windows\\System32\\SecurityHealthSystray.exe\" ",
"CreateTime": "2025-03-06T17:51:05+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "SecurityHealth",
"Offset(V)": 145201826054336,
"PID": 1860,
"PPID": 4912,
"Path": "C:\\Windows\\System32\\SecurityHealthSystray.exe",
"SessionId": 2,
"Threads": 2,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --no-startup-window --win-session-start",
"CreateTime": "2025-03-06T17:51:05+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201826906304,
"PID": 3952,
"PPID": 4912,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 61,
"Wow64": false,
"__children": [
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=renderer --string-annotations --instant-process --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=21 --time-ticks-at-unix-epoch=-1741283277737123 --launch-time-ticks=556708795 --always-read-main-dll --field-trial-handle=3928,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=3996 /prefetch:1",
"CreateTime": "2025-03-06T17:57:14+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201787768960,
"PID": 5348,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 19,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --string-annotations --always-read-main-dll --field-trial-handle=6740,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=6732 /prefetch:8",
"CreateTime": "2025-03-06T17:57:52+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201832050880,
"PID": 3876,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 8,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=7016,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=7128 /prefetch:8",
"CreateTime": "2025-03-06T17:57:59+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201827619008,
"PID": 5604,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 14,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5520,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=5608 /prefetch:8",
"CreateTime": "2025-03-06T17:57:16+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201827774656,
"PID": 1000,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 9,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=31 --time-ticks-at-unix-epoch=-1741283277737123 --launch-time-ticks=596993509 --always-read-main-dll --field-trial-handle=6904,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=7092 /prefetch:1",
"CreateTime": "2025-03-06T17:57:54+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201839592000,
"PID": 7080,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 15,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=35 --time-ticks-at-unix-epoch=-1741283277737123 --launch-time-ticks=625057436 --always-read-main-dll --field-trial-handle=5592,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=5688 /prefetch:1",
"CreateTime": "2025-03-06T17:58:23+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201828201216,
"PID": 5132,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 17,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=36 --time-ticks-at-unix-epoch=-1741283277737123 --launch-time-ticks=625148972 --always-read-main-dll --field-trial-handle=7112,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=6396 /prefetch:1",
"CreateTime": "2025-03-06T17:58:23+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201839919232,
"PID": 5388,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 15,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations --always-read-main-dll --field-trial-handle=2180,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=2512 /prefetch:3",
"CreateTime": "2025-03-06T17:51:14+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201835704512,
"PID": 6448,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 16,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": null,
"CreateTime": "2025-03-06T17:51:16+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201668321408,
"PID": 6672,
"PPID": 3952,
"Path": null,
"SessionId": 2,
"Threads": 9,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=utility --utility-sub-type=price_comparison_service.mojom.DataProcessor --lang=en-US --service-sandbox-type=entity_extraction --string-annotations --always-read-main-dll --field-trial-handle=6188,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=6580 /prefetch:8",
"CreateTime": "2025-03-06T17:58:44+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201830273728,
"PID": 6064,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 9,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe\" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2472,i,15721868202469256575,6833569417170289141,262144 --variations-seed-version --mojo-platform-channel-handle=2468 /prefetch:2",
"CreateTime": "2025-03-06T17:51:14+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201834049728,
"PID": 6456,
"PPID": 3952,
"Path": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"SessionId": 2,
"Threads": 15,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"Cmd": null,
"CreateTime": "2025-03-06T17:51:11+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "msedge.exe",
"Offset(V)": 145201786340096,
"PID": 6204,
"PPID": 3952,
"Path": null,
"SessionId": 2,
"Threads": 8,
"Wow64": false,
"__children": []
}
]
},
{
"Audit": "\\Device\\HarddiskVolume4\\Users\\generic-user\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe",
"Cmd": "\"C:\\Users\\generic-user\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe\" /background",
"CreateTime": "2025-03-06T17:51:11+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "OneDrive.exe",
"Offset(V)": 145201834340544,
"PID": 6160,
"PPID": 4912,
"Path": "C:\\Users\\generic-user\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe",
"SessionId": 2,
"Threads": 22,
"Wow64": true,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\cmd.exe",
"Cmd": "\"C:\\Windows\\system32\\cmd.exe\" ",
"CreateTime": "2025-03-06T17:51:44+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "cmd.exe",
"Offset(V)": 145201834332288,
"PID": 784,
"PPID": 4912,
"Path": "C:\\Windows\\system32\\cmd.exe",
"SessionId": 2,
"Threads": 1,
"Wow64": false,
"__children": [
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\conhost.exe",
"Cmd": null,
"CreateTime": "2025-03-06T17:51:49+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "conhost.exe",
"Offset(V)": 145201834446976,
"PID": 3896,
"PPID": 784,
"Path": null,
"SessionId": 2,
"Threads": 3,
"Wow64": false,
"__children": []
}
]
},
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\notepad.exe",
"Cmd": "\"C:\\Windows\\system32\\notepad.exe\" ",
"CreateTime": "2025-03-06T17:52:33+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "notepad.exe",
"Offset(V)": 145201839497344,
"PID": 2968,
"PPID": 4912,
"Path": "C:\\Windows\\system32\\notepad.exe",
"SessionId": 2,
"Threads": 4,
"Wow64": false,
"__children": []
}
]
}
]
},
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\fontdrvhost.exe",
"Cmd": null,
"CreateTime": "2025-03-06T17:49:42+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "fontdrvhost.ex",
"Offset(V)": 145201770697088,
"PID": 3812,
"PPID": 3616,
"Path": null,
"SessionId": 2,
"Threads": 5,
"Wow64": false,
"__children": []
},
{
"Audit": "\\Device\\HarddiskVolume4\\Windows\\System32\\dwm.exe",
"Cmd": "\"dwm.exe\"",
"CreateTime": "2025-03-06T17:49:42+00:00",
"ExitTime": null,
"Handles": null,
"ImageFileName": "dwm.exe",
"Offset(V)": 145201770352768,
"PID": 3860,
"PPID": 3616,
"Path": "C:\\Windows\\system32\\dwm.exe",
"SessionId": 2,
"Threads": 16,
"Wow64": false,
"__children": []
}
]
}
}
@@ -0,0 +1,100 @@
{
"WINDOWS10_GENERIC": [
{
"Offset": 213323072327680,
"__children": []
},
{
"Offset": 213323069669376,
"__children": []
},
{
"Offset": 213323011252224,
"__children": []
},
{
"Offset": 213322964488192,
"__children": []
},
{
"Offset": 213323011387392,
"__children": []
},
{
"Offset": 213322962362368,
"__children": []
},
{
"Offset": 213323041546240,
"__children": []
},
{
"Offset": 213323013046272,
"__children": []
},
{
"Offset": 213323061571584,
"__children": []
},
{
"Offset": 213323079548928,
"__children": []
},
{
"Offset": 213323067502592,
"__children": []
},
{
"Offset": 213323081900032,
"__children": []
},
{
"Offset": 213322954362880,
"__children": []
},
{
"Offset": 213322954346496,
"__children": []
},
{
"Offset": 213323014123520,
"__children": []
},
{
"Offset": 213323067707392,
"__children": []
},
{
"Offset": 213323070193664,
"__children": []
},
{
"Offset": 213323078791168,
"__children": []
},
{
"Offset": 213323069112320,
"__children": []
},
{
"Offset": 213323047776256,
"__children": []
},
{
"Offset": 213323013799936,
"__children": []
},
{
"Offset": 213322954985472,
"__children": []
},
{
"Offset": 213322954969088,
"__children": []
},
{
"Offset": 213323048636416,
"__children": []
}
]
}
@@ -0,0 +1,61 @@
{
"WINDOWS10_GENERIC": [
{
"Data": "",
"Hive Offset": 213322954346496,
"Key": "[NONAME]",
"Last Write Time": "2025-03-06T17:59:19+00:00",
"Name": "A",
"Type": "Key",
"Volatile": false
},
{
"Data": "",
"Hive Offset": 213322954362880,
"Key": "\\REGISTRY\\MACHINE\\SYSTEM",
"Last Write Time": "2019-12-07T09:15:07+00:00",
"Name": "ControlSet001",
"Type": "Key",
"Volatile": false
},
{
"Data": "",
"Hive Offset": 213322964488192,
"Key": "\\SystemRoot\\System32\\Config\\SOFTWARE",
"Last Write Time": "2025-03-06T17:38:01+00:00",
"Name": "Classes",
"Type": "Key",
"Volatile": false
},
{
"Data": "",
"Hive Offset": 213323011252224,
"Key": "\\SystemRoot\\System32\\Config\\SAM",
"Last Write Time": "2025-01-31T13:01:49+00:00",
"Name": "SAM",
"Type": "Key",
"Volatile": false,
"__children": []
},
{
"Data": "",
"Hive Offset": 213323048636416,
"Key": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Last Write Time": "2025-03-06T17:50:04+00:00",
"Name": "SOFTWARE",
"Type": "Key",
"Volatile": false,
"__children": []
},
{
"Data": "",
"Hive Offset": 213323047776256,
"Key": "\\??\\C:\\Users\\generic-user\\AppData\\Local\\Microsoft\\Windows\\UsrClass.dat",
"Last Write Time": "2025-03-05T18:36:09+00:00",
"Name": ".eip",
"Type": "Key",
"Volatile": false,
"__children": []
}
]
}
@@ -0,0 +1,123 @@
{
"WINDOWS10_GENERIC": {
"Count": null,
"Focus Count": null,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": null,
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": null,
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "",
"Time Focused": null,
"Type": "Key",
"__children": [
{
"Count": 7,
"Focus Count": 0,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": "2025-03-05T18:34:13+00:00",
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": "%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Paint.lnk",
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "\"\n00 00 00 00 07 00 00 00 00 00 00 00 07 00 00 00 ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf ff ff ff ff 90 86 6b 31 ..............k1\nfd 8d db 01 00 00 00 00 ........ \"",
"Time Focused": "0:00:00.507000",
"Type": "Value",
"__children": []
},
{
"Count": 1,
"Focus Count": 0,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": "2025-03-06T12:46:34+00:00",
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": "%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\Registry Editor.lnk",
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "\"\n00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf ff ff ff ff f0 82 cf ca ................\n95 8e db 01 00 00 00 00 ........ \"",
"Time Focused": "0:00:00.501000",
"Type": "Value",
"__children": []
},
{
"Count": 4,
"Focus Count": 0,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": "2025-03-06T17:36:33+00:00",
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": "%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk",
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "\"\n00 00 00 00 04 00 00 00 00 00 00 00 04 00 00 00 ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf ff ff ff ff 10 67 cf 4d .............g.M\nbe 8e db 01 00 00 00 00 ........ \"",
"Time Focused": "0:00:00.504000",
"Type": "Value",
"__children": []
},
{
"Count": 1,
"Focus Count": 0,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": "2025-03-06T17:51:44+00:00",
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": "%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools\\Command Prompt.lnk",
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "\"\n00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf ff ff ff ff d0 99 66 6c ..............fl\nc0 8e db 01 00 00 00 00 ........ \"",
"Time Focused": "0:00:00.501000",
"Type": "Value",
"__children": []
},
{
"Count": 1,
"Focus Count": 0,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": "2025-03-06T17:52:33+00:00",
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": "%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Notepad.lnk",
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "\"\n00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf ff ff ff ff 00 62 ba 89 .............b..\nc0 8e db 01 00 00 00 00 ........ \"",
"Time Focused": "0:00:00.501000",
"Type": "Value",
"__children": []
},
{
"Count": 2,
"Focus Count": 0,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": "2025-03-06T17:56:50+00:00",
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": "%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\Task Scheduler.lnk",
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "\"\n00 00 00 00 02 00 00 00 00 00 00 00 02 00 00 00 ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf ff ff ff ff b0 24 49 23 .............$I#\nc1 8e db 01 00 00 00 00 ........ \"",
"Time Focused": "0:00:00.502000",
"Type": "Value",
"__children": []
},
{
"Count": 1,
"Focus Count": 0,
"Hive Name": "\\??\\C:\\Users\\generic-user\\ntuser.dat",
"Hive Offset": 213323048636416,
"ID": null,
"Last Updated": "2025-03-06T17:57:09+00:00",
"Last Write Time": "2025-03-06T17:57:09+00:00",
"Name": "%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Microsoft Edge.lnk",
"Path": "ntuser.dat\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count",
"Raw Data": "\"\n00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf ................\n00 00 80 bf 00 00 80 bf ff ff ff ff 60 3d 89 2e ............`=..\nc1 8e db 01 00 00 00 00 ........ \"",
"Time Focused": "0:00:00.501000",
"Type": "Value",
"__children": []
}
]
}
}
@@ -0,0 +1,36 @@
{
"WINDOWS10_GENERIC": [
{
"Create Time": "2025-03-06T17:48:02+00:00",
"Process": "System",
"Process ID": 4
},
{
"Create Time": "2025-03-06T17:48:37+00:00",
"Process": "lsass.exe",
"Process ID": 696,
"Session ID": 0,
"Session Type": null,
"User Name": "/SYSTEM",
"__children": []
},
{
"Create Time": "2025-03-06T17:49:03+00:00",
"Process": "MsMpEng.exe",
"Process ID": 1956,
"Session ID": 0,
"Session Type": null,
"User Name": "WORKGROUP/Windows-generic$",
"__children": []
},
{
"Create Time": "2025-03-06T17:50:08+00:00",
"Process": "rdpclip.exe",
"Process ID": 4180,
"Session ID": 2,
"Session Type": null,
"User Name": "Windows-generic/generic-user",
"__children": []
}
]
}
@@ -0,0 +1,41 @@
{
"WINDOWS10_GENERIC":
[
{
"Exec Flag": null,
"File Path": "C:\\Windows\\System32\\cmdl32.exe",
"File Size": null,
"Last Modified": "2019-12-07T09:09:07+00:00",
"Last Update": null,
"Order": 0,
"__children": []
},
{
"Exec Flag": null,
"File Path": "C:\\Windows\\System32\\cmdkey.exe",
"File Size": null,
"Last Modified": "2019-12-07T09:09:09+00:00",
"Last Update": null,
"Order": 1,
"__children": []
},
{
"Exec Flag": null,
"File Path": "C:\\Windows\\system32\\whoami.exe",
"File Size": null,
"Last Modified": "2019-12-07T09:09:51+00:00",
"Last Update": null,
"Order": 2,
"__children": []
},
{
"Exec Flag": null,
"File Path": null,
"File Size": null,
"Last Modified": "2023-12-13T16:43:28+00:00",
"Last Update": null,
"Order": 3,
"__children": []
}
]
}
@@ -0,0 +1,684 @@
{
"WINDOWSXP_GENERIC": [
{
"DueTime": "0x00000001:0xb6912640",
"Module": "ntoskrnl",
"Offset": 2180960760,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xe2e5d9fc",
"Module": "ks",
"Offset": 2181100944,
"Period(ms)": 0,
"Routine": 4162614588,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x80000001:0x838d66d0",
"Module": "ntoskrnl",
"Offset": 2180726816,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xbe54efd0",
"Module": "NDIS",
"Offset": 2182586488,
"Period(ms)": 60000,
"Routine": 4164630316,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x80000000:0x6d915dc0",
"Module": "ntoskrnl",
"Offset": 2182771520,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xd5616870",
"Module": "HTTP",
"Offset": 4122586976,
"Period(ms)": 0,
"Routine": 4122527634,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa92535f",
"Module": "USBPORT",
"Offset": 2179614512,
"Period(ms)": 0,
"Routine": 4163343596,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x80000000:0x28ec7d80",
"Module": "ntoskrnl",
"Offset": 2167895896,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xd5f1ddd0",
"Module": "afd",
"Offset": 4289149728,
"Period(ms)": 0,
"Routine": 4146614848,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xe64e9c50",
"Module": "ntoskrnl",
"Offset": 4289091536,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000002:0x10691f50",
"Module": "BATTC",
"Offset": 2182647568,
"Period(ms)": 0,
"Routine": 4170619626,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000002:0x10691f50",
"Module": "BATTC",
"Offset": 2184852912,
"Period(ms)": 0,
"Routine": 4170619626,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xe650bd40",
"Module": "ntoskrnl",
"Offset": 4289091352,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xaf39aa70",
"Module": "watchdog",
"Offset": 2182133296,
"Period(ms)": 10000,
"Routine": 4170290884,
"Signaled": "Yes",
"Symbol": "_imp__KdSave",
"__children": []
},
{
"DueTime": "0x00000001:0xaf39aa70",
"Module": "watchdog",
"Offset": 2181849992,
"Period(ms)": 10000,
"Routine": 4170290884,
"Signaled": "Yes",
"Symbol": "_imp__KdSave",
"__children": []
},
{
"DueTime": "0x00000008:0x61e17090",
"Module": "ntoskrnl",
"Offset": 2153125248,
"Period(ms)": 0,
"Routine": 2152824977,
"Signaled": "-",
"Symbol": "ExpTimeRefreshDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xa9537f40",
"Module": "ntoskrnl",
"Offset": 2153083360,
"Period(ms)": 0,
"Routine": 2152814203,
"Signaled": "-",
"Symbol": "CmpLazyFlushDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xc5addbe0",
"Module": "TDI",
"Offset": 4147138000,
"Period(ms)": 0,
"Routine": 4169831408,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaadb3be0",
"Module": "netbt",
"Offset": 2182155920,
"Period(ms)": 0,
"Routine": 4146697354,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaadb9040",
"Module": "TDI",
"Offset": 2182059040,
"Period(ms)": 0,
"Routine": 4169831408,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xa9537f40",
"Module": "ntoskrnl",
"Offset": 2153083360,
"Period(ms)": 0,
"Routine": 2152814203,
"Signaled": "-",
"Symbol": "CmpLazyFlushDpcRoutine",
"__children": []
},
{
"DueTime": "0x80000000:0x19eae820",
"Module": "ntoskrnl",
"Offset": 2182169704,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xaa9b2a20",
"Module": "NDIS",
"Offset": 2179568032,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000002:0x1a97a160",
"Module": "Ntfs",
"Offset": 4164841808,
"Period(ms)": 0,
"Routine": 4164732734,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x80000000:0x2c5fb7e0",
"Module": "ntoskrnl",
"Offset": 2180369200,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000002:0x3dcf47a0",
"Module": "afd",
"Offset": 2183169664,
"Period(ms)": 0,
"Routine": 4146614848,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xc4906e60",
"Module": "rdbss",
"Offset": 4146422176,
"Period(ms)": 0,
"Routine": 4146381701,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa92535f",
"Module": "USBPORT",
"Offset": 2179614512,
"Period(ms)": 0,
"Routine": 4163343596,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa8619e0",
"Module": "TDI",
"Offset": 2182064136,
"Period(ms)": 0,
"Routine": 4169831408,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xc45ec240",
"Module": "tcpip",
"Offset": 4147157776,
"Period(ms)": 100,
"Routine": 4146861021,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x80000000:0x35b72850",
"Module": "ntoskrnl",
"Offset": 2180437784,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xaad6fab0",
"Module": "NDIS",
"Offset": 2181321392,
"Period(ms)": 1000,
"Routine": 4164630316,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaadb9040",
"Module": "TDI",
"Offset": 2182059040,
"Period(ms)": 0,
"Routine": 4169831408,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xa9537f40",
"Module": "ntoskrnl",
"Offset": 2153083360,
"Period(ms)": 0,
"Routine": 2152814203,
"Signaled": "-",
"Symbol": "CmpLazyFlushDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xe2e5ee70",
"Module": "ipsec",
"Offset": 4147285920,
"Period(ms)": 60000,
"Routine": 4147221715,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xe2e5ee70",
"Module": "ipsec",
"Offset": 4147284744,
"Period(ms)": 0,
"Routine": 4147221577,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xe2e5d9fc",
"Module": "ks",
"Offset": 2181100944,
"Period(ms)": 0,
"Routine": 4162614588,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000098:0xa67683e0",
"Module": "NDIS",
"Offset": 2183038120,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xa6beb810",
"Module": "ntoskrnl",
"Offset": 2153086208,
"Period(ms)": 1000,
"Routine": 2152611575,
"Signaled": "Yes",
"Symbol": "IopTimerDispatch",
"__children": []
},
{
"DueTime": "0x00000001:0xe2f53650",
"Module": "ipnat",
"Offset": 4146164320,
"Period(ms)": 60000,
"Routine": 4146134936,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x80000001:0x838d66d0",
"Module": "ntoskrnl",
"Offset": 2180726816,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xa6c34da0",
"Module": "ntoskrnl",
"Offset": 2153118912,
"Period(ms)": 1000,
"Routine": 2152615232,
"Signaled": "Yes",
"Symbol": "PopScanIdleList",
"__children": []
},
{
"DueTime": "0x00000098:0xa67683e0",
"Module": "NDIS",
"Offset": 2183038120,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xa6d41cb0",
"Module": "ntoskrnl",
"Offset": 2153080200,
"Period(ms)": 0,
"Routine": 2152616496,
"Signaled": "-",
"Symbol": "CcScanDpc",
"__children": []
},
{
"DueTime": "0x80000000:0x14500b10",
"Module": "ntoskrnl",
"Offset": 2182113448,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xaba81b20",
"Module": "NDIS",
"Offset": 2182656416,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xab110bd0",
"Module": "ntoskrnl",
"Offset": 2181090272,
"Period(ms)": 0,
"Routine": 2152754200,
"Signaled": "-",
"Symbol": "CcPfTraceTimerRoutine",
"__children": []
},
{
"DueTime": "0x00000098:0xa6ad86a0",
"Module": "NDIS",
"Offset": 2182615456,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xd56a01e0",
"Module": "HTTP",
"Offset": 4122576520,
"Period(ms)": 60000,
"Routine": 4122481076,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xd56a7ca0",
"Module": "HTTP",
"Offset": 4122577120,
"Period(ms)": 30000,
"Routine": 4122510208,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xd56a7ca0",
"Module": "HTTP",
"Offset": 4122586816,
"Period(ms)": 0,
"Routine": 4122536296,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x80000000:0x14500b10",
"Module": "ntoskrnl",
"Offset": 2182113448,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000002:0x10691f50",
"Module": "BATTC",
"Offset": 2184852912,
"Period(ms)": 0,
"Routine": 4170619626,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000002:0x10691f50",
"Module": "BATTC",
"Offset": 2182647568,
"Period(ms)": 0,
"Routine": 4170619626,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa90b010",
"Module": "sr",
"Offset": 2184659528,
"Period(ms)": 0,
"Routine": 4165384494,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000131:0x3cf80b10",
"Module": "NDIS",
"Offset": 2181526704,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa9b2a20",
"Module": "NDIS",
"Offset": 2179568032,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa9cb150",
"Module": "NDIS",
"Offset": 2179569720,
"Period(ms)": 0,
"Routine": 4164628447,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa9e70c0",
"Module": "ntoskrnl",
"Offset": 2182248232,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xd56bd340",
"Module": "srv",
"Offset": 4128143248,
"Period(ms)": 0,
"Routine": 4128080773,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xbae86a40",
"Module": "ntoskrnl",
"Offset": 2182222184,
"Period(ms)": 0,
"Routine": 2152618407,
"Signaled": "-",
"Symbol": "ExpTimerDpcRoutine",
"__children": []
},
{
"DueTime": "0x00000001:0xacafcdd0",
"Module": "Ntfs",
"Offset": 4164841712,
"Period(ms)": 0,
"Routine": 4164719155,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaa92535f",
"Module": "USBPORT",
"Offset": 2179614512,
"Period(ms)": 0,
"Routine": 4163343596,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xad54f9d0",
"Module": "ntoskrnl",
"Offset": 2153085904,
"Period(ms)": 60000,
"Routine": 2152638914,
"Signaled": "Yes",
"Symbol": "IopIrpStackProfilerTimer",
"__children": []
},
{
"DueTime": "0x00000008:0x73b44670",
"Module": "ipsec",
"Offset": 4147284848,
"Period(ms)": 0,
"Routine": 4147221577,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaad6c270",
"Module": "NDIS",
"Offset": 2179663392,
"Period(ms)": 0,
"Routine": 4164642677,
"Signaled": "-",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000001:0xaad6fab0",
"Module": "NDIS",
"Offset": 2181321392,
"Period(ms)": 1000,
"Routine": 4164630316,
"Signaled": "Yes",
"Symbol": null,
"__children": []
},
{
"DueTime": "0x00000008:0x73bef8c0",
"Module": "netbt",
"Offset": 2182155520,
"Period(ms)": 0,
"Routine": 4146697354,
"Signaled": "-",
"Symbol": null,
"__children": []
}
]
}
@@ -0,0 +1,67 @@
{
"WINDOWS10_GENERIC": [
{
"EndAddress": 18446735295750344704,
"Name": "hwpolicy.sys",
"StartAddress": 18446735295750275072,
"Time": "2025-03-06T17:47:55+00:00",
"__children": []
},
{
"EndAddress": 18446735295728652288,
"Name": "WdBoot.sys",
"StartAddress": 18446735295728582656,
"Time": "2025-03-06T17:47:56+00:00",
"__children": []
},
{
"EndAddress": 18446735295786053632,
"Name": "dam.sys",
"StartAddress": 18446735295785926656,
"Time": "2025-03-06T17:48:02+00:00",
"__children": []
},
{
"EndAddress": 18446735295788797952,
"Name": "serial.sys",
"StartAddress": 18446735295788679168,
"Time": "2025-03-06T17:48:21+00:00",
"__children": []
},
{
"EndAddress": 18446735295788875776,
"Name": "serenum.sys",
"StartAddress": 18446735295788810240,
"Time": "2025-03-06T17:48:21+00:00",
"__children": []
},
{
"EndAddress": 18446735295761932288,
"Name": "dump_dumpfve.sys",
"StartAddress": 18446735295761809408,
"Time": "2025-03-06T17:48:27+00:00",
"__children": []
},
{
"EndAddress": 18446735295761629184,
"Name": "dump_vmbkmcl.sys",
"StartAddress": 18446735295761481728,
"Time": "2025-03-06T17:48:27+00:00",
"__children": []
},
{
"EndAddress": 18446735295761481728,
"Name": "dump_storvsc.sys",
"StartAddress": 18446735295761416192,
"Time": "2025-03-06T17:48:27+00:00",
"__children": []
},
{
"EndAddress": 18446735295761350656,
"Name": "dump_storport.sys",
"StartAddress": 18446735295761285120,
"Time": "2025-03-06T17:48:27+00:00",
"__children": []
}
]
}
@@ -0,0 +1,94 @@
{
"WINDOWS10_GENERIC": [
{
"CommitCharge": 1,
"End VPN": 2147381247,
"File": null,
"File output": "Disabled",
"Offset": 18446607800399740208,
"PID": 4,
"Parent": 0,
"PrivateMemory": 1,
"Process": "System",
"Protection": "PAGE_READONLY",
"Start VPN": 2147377152,
"Tag": "VadS",
"__children": []
},
{
"CommitCharge": 1,
"End VPN": 2147356671,
"File": null,
"File output": "Disabled",
"Offset": 18446607800399739968,
"PID": 4,
"Parent": 18446607800399740208,
"PrivateMemory": 1,
"Process": "System",
"Protection": "PAGE_READONLY",
"Start VPN": 2147352576,
"Tag": "VadS",
"__children": []
},
{
"CommitCharge": 9,
"End VPN": 2004303871,
"File": "\\Windows\\SysWOW64\\ntdll.dll",
"File output": "Disabled",
"Offset": 18446607800410763840,
"PID": 4,
"Parent": 18446607800399739968,
"PrivateMemory": 0,
"Process": "System",
"Protection": "PAGE_EXECUTE_WRITECOPY",
"Start VPN": 2002583552,
"Tag": "Vad ",
"__children": []
},
{
"CommitCharge": 9,
"End VPN": 140703785033727,
"File": "\\Windows\\System32\\vertdll.dll",
"File output": "Disabled",
"Offset": 18446607800410768000,
"PID": 4,
"Parent": 18446607800399740208,
"PrivateMemory": 0,
"Process": "System",
"Protection": "PAGE_EXECUTE_WRITECOPY",
"Start VPN": 140703784828928,
"Tag": "Vad ",
"__children": []
},
{
"CommitCharge": 0,
"End VPN": 2873390796799,
"File": null,
"File output": "Disabled",
"Offset": 18446607800474375600,
"PID": 4,
"Parent": 18446607800410768000,
"PrivateMemory": 0,
"Process": "System",
"Protection": "PAGE_READWRITE",
"Start VPN": 2873390792704,
"Tag": "Vad ",
"__children": []
},
{
"CommitCharge": 16,
"End VPN": 140703787155455,
"File": "\\Windows\\System32\\ntdll.dll",
"File output": "Disabled",
"Offset": 18446607800410767520,
"PID": 4,
"Parent": 18446607800410768000,
"PrivateMemory": 0,
"Process": "System",
"Protection": "PAGE_EXECUTE_WRITECOPY",
"Start VPN": 140703785091072,
"Tag": "Vad ",
"__children": []
}
]
}
@@ -0,0 +1,76 @@
{
"WINDOWS10_GENERIC": [
{
"End": 2147381247,
"Left": 145201666899008,
"Offset": 145201666899248,
"PID": 4,
"Parent": 0,
"Process": "System",
"Right": 145201677927040,
"Start": 2147377152,
"Tag": "VadS",
"__children": []
},
{
"End": 2147356671,
"Left": 145201677922880,
"Offset": 145201666899008,
"PID": 4,
"Parent": 145201666899248,
"Process": "System",
"Right": 0,
"Start": 2147352576,
"Tag": "VadS",
"__children": []
},
{
"End": 2004303871,
"Left": 0,
"Offset": 145201677922880,
"PID": 4,
"Parent": 145201666899008,
"Process": "System",
"Right": 0,
"Start": 2002583552,
"Tag": "Vad ",
"__children": []
},
{
"End": 140703785033727,
"Left": 145201741534640,
"Offset": 145201677927040,
"PID": 4,
"Parent": 145201666899248,
"Process": "System",
"Right": 145201677926560,
"Start": 140703784828928,
"Tag": "Vad ",
"__children": []
},
{
"End": 2873390796799,
"Left": 0,
"Offset": 145201741534640,
"PID": 4,
"Parent": 145201677927040,
"Process": "System",
"Right": 0,
"Start": 2873390792704,
"Tag": "Vad ",
"__children": []
},
{
"End": 140703787155455,
"Left": 0,
"Offset": 145201677926560,
"PID": 4,
"Parent": 145201677927040,
"Process": "System",
"Right": 0,
"Start": 140703785091072,
"Tag": "Vad ",
"__children": []
}
]
}
@@ -0,0 +1,82 @@
{
"WINDOWS10_GENERIC": [
{
"End offset": 17592186044416,
"Region": "MiVaBootLoaded",
"Start offset": 238594023227392,
"__children": []
},
{
"End offset": 549755813888,
"Region": "MiVaDriverImages",
"Start offset": 272678883688448,
"__children": []
},
{
"End offset": 549755813888,
"Region": "MiVaHal",
"Start offset": 258385232527360,
"__children": []
},
{
"End offset": 3848290697216,
"Region": "MiVaNonPagedPool",
"Start offset": 266081813921792,
"__children": []
},
{
"End offset": 2748779069440,
"Region": "MiVaPagedPool",
"Start offset": 278135644927560,
"__children": []
},
{
"End offset": 17592186044416,
"Region": "MiVaPfnDatabase",
"Start offset": 166026255794176,
"__children": []
},
{
"End offset": 17592186044416,
"Region": "MiVaProcessSpace",
"Start offset": 191315023233024,
"__children": []
},
{
"End offset": 549755813888,
"Region": "MiVaSessionGlobalSpace",
"Start offset": 186367220908032,
"__children": []
},
{
"End offset": 17592186044416,
"Region": "MiVaSessionSpace",
"Start offset": 213305255788544,
"__children": []
},
{
"End offset": 1099511627776,
"Region": "MiVaSpecialPoolPaged",
"Start offset": 261683767410688,
"__children": []
},
{
"End offset": 1099511627776,
"Region": "MiVaSystemCache",
"Start offset": 208907209277440,
"__children": []
},
{
"End offset": 549755813888,
"Region": "MiVaSystemPtes",
"Start offset": 274328151130112,
"__children": []
},
{
"End offset": 17592186044416,
"Region": "MiVaUnused",
"Start offset": 145135534866432,
"__children": []
}
]
}
File diff suppressed because it is too large Load Diff
+106 -10
View File
@@ -11,8 +11,15 @@ import sys
import tempfile
import contextlib
import functools
import json
import logging
from typing import List, Tuple
from test import WINDOWS_TESTS_DATA_DIR
test_logger = logging.getLogger(__name__)
#
# HELPER FUNCTIONS
#
@@ -55,9 +62,9 @@ def runvol_plugin(
return runvol(args, volatility, python)
def runvolshell(img, volshell, python, volshellargs=None, globalargs=None):
volshellargs = volshellargs or []
globalargs = globalargs or []
def runvolshell(
img, volshell, python, volshellargs: Tuple = (), globalargs: Tuple = ()
):
args = (
globalargs
+ (
@@ -71,25 +78,100 @@ def runvolshell(img, volshell, python, volshellargs=None, globalargs=None):
return runvol(args, volshell, python)
def load_test_data(plugin: str, test_key: str):
if plugin.startswith("windows."):
data_path = WINDOWS_TESTS_DATA_DIR / f"{plugin}.json"
# TODO: add Linux and macOS when any of these requires this API
else:
raise Exception(f"Cannot determine OS of plugin: {plugin}")
if not data_path.exists():
raise FileNotFoundError(
f"Test data not found for plugin {plugin} at {data_path}"
)
with open(data_path) as f:
# This will raise an explicit exception by itself on failures
return json.load(f)[test_key]
def dict_lower_strvalues(dict_to_convert: dict):
"""Lower each value of type string of a dictionary
Args:
dict_to_convert: The dictionary in which to lower the string values
Returns:
A copy of the dictionary with lowered string values
"""
converted = {}
for key, value in dict_to_convert.items():
if isinstance(value, str):
converted[key] = value.lower()
else:
converted[key] = value
return converted
def match_output_row(
expected_row: dict, plugin_json_out: List[dict], exact_match: bool = False
expected_row: dict,
plugin_json_out: List[dict],
exact_match: bool = False,
case_sensitive: bool = True,
children_recursive: bool = False,
):
"""Search each row of a plugin's JSON output for an expected row. Each row is a dict.
"""Search each row in a plugin's JSON output for a matching row.
This method supports recursive comparisons using the "__children" key, making it useful for testing hierarchical plugins like windows.pstree.
It also maintains case sensitivity and exact matching behavior when traversing nested structures.
Args:
expected_row: The expected row to be found in the output
plugin_json_out: The plugin's output in JSON format (typically obtained through -r json and json.loads)
exact_match: Whether to require exactly the expected row, no more no less, or to anticipate columns' addition by checking only
exact_match: Require exactly the expected row, no more no less, or anticipate columns' addition by checking only
the expected row keys and values
case_sensitive: Operate case sensitive match for str values of both dictionaries or not
children_recursive: Perform a recursive match by inspecting "__children" keys of each expected_row
Returns:
A boolean indicating whether a match was found or not
"""
# Lower each string value of both dicts
if not case_sensitive:
expected_row = dict_lower_strvalues(expected_row)
plugin_json_out_tmp = []
for row in plugin_json_out:
plugin_json_out_tmp.append(dict_lower_strvalues(row))
plugin_json_out = plugin_json_out_tmp
if not exact_match:
for row in plugin_json_out:
if all(
expected_item in row.items() for expected_item in expected_row.items()
expected_item in row.items()
for expected_item in expected_row.items()
if not expected_item[0] == "__children"
):
return True
if (
children_recursive
and "__children" in expected_row
and "__children" in row
):
for children_expected_row in expected_row["__children"]:
if not match_output_row(
children_expected_row,
row["__children"],
case_sensitive=case_sensitive,
children_recursive=True,
):
break
else:
# We matched all the children keys
return True
else:
# No recursion required and we already matched the row
return True
else:
# No "__children" recursion here as we want to match the whole tree at once
for row in plugin_json_out:
if expected_row == row:
return True
@@ -97,12 +179,26 @@ def match_output_row(
return False
def count_entries_flat(plugin_json_out: List[dict]):
"""Count the number of entries as if -r json wasn't specified. Allows to get a non-hierarchical count, without running a plugin twice
(once with "-r json" and once without) while still preserving JSON features.
Args:
plugin_json_out: The plugin's output in JSON format (typically obtained through -r json and json.loads)
"""
# Remove whitespaces between entries
# If a value contains {", it will be represented by {\" so no confusion
return json.dumps(plugin_json_out, separators=(",", ":")).count('{"')
#
# TESTS
#
def basic_volshell_test(image, volatility, python, globalargs):
def basic_volshell_test(
image, volatility, python, volshellargs: Tuple = (), globalargs: Tuple = ()
):
# Basic VolShell test to verify requirements and ensure VolShell runs without crashing
volshell_commands = [
@@ -122,7 +218,7 @@ def basic_volshell_test(image, volatility, python, globalargs):
img=image,
volshell=volatility,
python=python,
volshellargs=("--script", filename),
volshellargs=("--script", filename) + volshellargs,
globalargs=globalargs,
)
finally:
+77 -30
View File
@@ -8,6 +8,7 @@ import random
import string
import struct
import sys
import textwrap
from typing import Any, Dict, Iterable, List, Optional, Tuple, Type, Union
from urllib import parse, request
@@ -23,6 +24,14 @@ try:
except ImportError:
has_capstone = False
try:
from IPython import terminal
from traitlets import config as traitlets_config
has_ipython = True
except ImportError:
has_ipython = False
class Volshell(interfaces.plugins.PluginInterface):
"""Shell environment to directly interact with a memory image."""
@@ -51,7 +60,13 @@ class Volshell(interfaces.plugins.PluginInterface):
description="File to load and execute at start",
default=None,
optional=True,
)
),
requirements.BooleanRequirement(
name="script-only",
description="Exit volshell after the script specified in --script completes",
default=False,
optional=True,
),
]
return reqs + [
requirements.TranslationLayerRequirement(
@@ -69,43 +84,70 @@ class Volshell(interfaces.plugins.PluginInterface):
"""
# Try to enable tab completion
try:
import readline
except ImportError:
pass
else:
import rlcompleter
if not has_ipython:
try:
import readline
import rlcompleter
completer = rlcompleter.Completer(namespace=self._construct_locals_dict())
readline.set_completer(completer.complete)
readline.parse_and_bind("tab: complete")
print("Readline imported successfully")
completer = rlcompleter.Completer(
namespace=self._construct_locals_dict()
)
readline.set_completer(completer.complete)
readline.parse_and_bind("tab: complete")
print("Readline imported successfully")
except ImportError:
print(
"Readline or rlcompleter module could not be imported. Tab completion will not be available."
)
# TODO: provide help, consider generic functions (pslist?) and/or providing windows/linux functions
mode = self.__module__.split(".")[-1]
mode = mode[0].upper() + mode[1:]
banner = f"""
Call help() to see available functions
banner = textwrap.dedent(
f"""
Call help() to see available functions
Volshell mode : {mode}
Current Layer : {self.current_layer}
Current Symbol Table : {self.current_symbol_table}
Current Kernel Name : {self.current_kernel_name}
"""
Volshell mode : {mode}
Current Layer : {self.current_layer}
Current Symbol Table : {self.current_symbol_table}
Current Kernel Name : {self.current_kernel_name}
"""
)
sys.ps1 = f"({self.current_layer}) >>> "
# Dict self._construct_locals_dict() will have priority on keys
combined_locals = additional_locals.copy()
combined_locals.update(self._construct_locals_dict())
self.__console = code.InteractiveConsole(locals=combined_locals)
if has_ipython:
class LayerNamePrompt(terminal.prompts.Prompts):
def in_prompt_tokens(self, cli=None):
slf = self.shell.user_ns.get("self")
layer_name = slf.current_layer if slf else "no_layer"
return [(terminal.prompts.Token.Prompt, f"[{layer_name}]> ")]
c = traitlets_config.Config()
c.TerminalInteractiveShell.prompts_class = LayerNamePrompt
c.InteractiveShellEmbed.banner2 = banner
self.__console = terminal.embed.InteractiveShellEmbed(
config=c, user_ns=combined_locals
)
else:
self.__console = code.InteractiveConsole(locals=combined_locals)
# Since we have to do work to add the option only once for all different modes of volshell, we can't
# rely on the default having been set
if self.config.get("script", None) is not None:
self.run_script(location=self.config["script"])
self.__console.interact(banner=banner)
if self.config.get("script-only"):
exit()
if has_ipython:
self.__console()
else:
self.__console.interact(banner=banner)
return renderers.TreeGrid([("Terminating", str)], None)
@@ -277,23 +319,25 @@ class Volshell(interfaces.plugins.PluginInterface):
self._display_data(offset, remaining_data)
def display_quadwords(
self, offset, count=DEFAULT_NUM_DISPLAY_BYTES, layer_name=None
self, offset, count=DEFAULT_NUM_DISPLAY_BYTES, layer_name=None, byteorder="@"
):
"""Displays quad-word values (8 bytes) and corresponding ASCII characters"""
remaining_data = self._read_data(offset, count=count, layer_name=layer_name)
self._display_data(offset, remaining_data, format_string="Q")
self._display_data(offset, remaining_data, format_string=f"{byteorder}Q")
def display_doublewords(
self, offset, count=DEFAULT_NUM_DISPLAY_BYTES, layer_name=None
self, offset, count=DEFAULT_NUM_DISPLAY_BYTES, layer_name=None, byteorder="@"
):
"""Displays double-word values (4 bytes) and corresponding ASCII characters"""
remaining_data = self._read_data(offset, count=count, layer_name=layer_name)
self._display_data(offset, remaining_data, format_string="I")
self._display_data(offset, remaining_data, format_string=f"{byteorder}I")
def display_words(self, offset, count=DEFAULT_NUM_DISPLAY_BYTES, layer_name=None):
def display_words(
self, offset, count=DEFAULT_NUM_DISPLAY_BYTES, layer_name=None, byteorder="@"
):
"""Displays word values (2 bytes) and corresponding ASCII characters"""
remaining_data = self._read_data(offset, count=count, layer_name=layer_name)
self._display_data(offset, remaining_data, format_string="H")
self._display_data(offset, remaining_data, format_string=f"{byteorder}H")
def regex_scan(self, pattern, count=DEFAULT_NUM_DISPLAY_BYTES, layer_name=None):
"""Scans for regex pattern in layer using RegExScanner."""
@@ -508,10 +552,13 @@ class Volshell(interfaces.plugins.PluginInterface):
location = "file:" + request.pathname2url(location)
print(f"Running code from {location}\n")
accessor = resources.ResourceAccessor()
with accessor.open(url=location) as fp:
self.__console.runsource(
io.TextIOWrapper(fp, encoding="utf-8").read(), symbol="exec"
)
with accessor.open(url=location) as handle, io.TextIOWrapper(
handle, encoding="utf-8"
) as fp:
if has_ipython:
self.__console.ex(fp.read())
else:
self.__console.runsource(fp.read(), symbol="exec")
print("\nCode complete")
def load_file(self, location: str):
+2 -2
View File
@@ -30,8 +30,8 @@ class Volshell(generic.Volshell):
requirements.ModuleRequirement(
name="kernel", description="Linux kernel module"
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.IntRequirement(
name="pid", description="Process ID", optional=True
+2 -2
View File
@@ -19,8 +19,8 @@ class Volshell(generic.Volshell):
requirements.ModuleRequirement(
name="kernel", description="Darwin kernel module"
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.IntRequirement(
name="pid", description="Process ID", optional=True
+2 -2
View File
@@ -17,8 +17,8 @@ class Volshell(generic.Volshell):
def get_requirements(cls):
return [
requirements.ModuleRequirement(name="kernel", description="Windows kernel"),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.IntRequirement(
name="pid", description="Process ID", optional=True
+1 -1
View File
@@ -1,6 +1,6 @@
# We use the SemVer 2.0.0 versioning scheme
VERSION_MAJOR = 2 # Number of releases of the library with a breaking change
VERSION_MINOR = 23 # Number of changes that only add to the interface
VERSION_MINOR = 25 # Number of changes that only add to the interface
VERSION_PATCH = 0 # Number of changes that do not change the interface
VERSION_SUFFIX = ""
+25 -3
View File
@@ -402,13 +402,35 @@ class Pointer(Integer):
pointer should be recast. The "pointer" must always live within
the space (even if the data provided is invalid).
"""
mask = context.layers[object_info.native_layer_name].address_mask
new = (
cls._get_raw_value(
context, data_format, object_info.layer_name, object_info.offset
)
& mask
)
return new
@classmethod
def _get_raw_value(
cls,
context: interfaces.context.ContextInterface,
data_format: DataFormatInfo,
layer_name: str,
offset: int,
) -> int:
length, endian, signed = data_format
if signed:
raise ValueError("Pointers cannot have signed values")
mask = context.layers[object_info.native_layer_name].address_mask
data = context.layers.read(object_info.layer_name, object_info.offset, length)
data = context.layers.read(layer_name, offset, length)
value = int.from_bytes(data, byteorder=endian, signed=signed)
return value & mask
return value
def get_raw_value(self) -> int:
raw = self._get_raw_value(
self._context, self.vol.data_format, self.vol.layer_name, self.vol.offset
)
return raw
def dereference(
self, layer_name: Optional[str] = None
+102 -12
View File
@@ -2,9 +2,11 @@
# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0
#
import re
from typing import Optional, Union
from volatility3.framework import interfaces, objects, constants
from volatility3.framework import interfaces, objects, constants, exceptions
def rol(value: int, count: int, max_bits: int = 64) -> int:
@@ -33,6 +35,7 @@ def array_to_string(
count: Optional[int] = None,
errors: str = "replace",
block_size=32,
encoding="utf-8",
) -> str:
"""Takes a Volatility 'Array' of characters and returns a Python string.
@@ -60,6 +63,7 @@ def array_to_string(
count=count,
errors=errors,
block_size=block_size,
encoding=encoding,
)
@@ -68,6 +72,7 @@ def pointer_to_string(
count: int,
errors: str = "replace",
block_size=32,
encoding="utf-8",
) -> str:
"""Takes a Volatility 'Pointer' to characters and returns a Python string.
@@ -94,9 +99,101 @@ def pointer_to_string(
count=count,
errors=errors,
block_size=block_size,
encoding=encoding,
)
def gather_contiguous_bytes_from_address(
context, data_layer, starting_address: int, count: int
) -> bytes:
"""
This method reconstructs a string from memory while also carefully examining each page
It goes page-by-page reading the bytes. This is done by calculating page boundaries
and then only reading one page at a time.
If a page is missing, the code initially catches the exception.
If data is non-empty (meaning at least one read succeeded), then we return what was read
If the first page fails, then we re-raise the exception
"""
data = b""
if isinstance(data_layer, interfaces.layers.TranslationLayerInterface):
last_address = starting_address
for address, length, _, _, _ in data_layer.mapping(
offset=starting_address, length=count, ignore_errors=True
):
# we hit a swapped out page
if last_address != address:
break
data += data_layer.read(address, length)
last_address = address + length
elif starting_address + count < data_layer.maximum_address:
data = data_layer.read(starting_address, count)
# if we were able to read from the first page, we want to try and construct the string
# if the first page fails -> throw exception
if data:
return data
else:
raise exceptions.InvalidAddressException(
layer_name=data_layer, invalid_address=starting_address
)
def bytes_to_decoded_string(
data: bytes, encoding: str, errors: str, return_truncated: bool = True
) -> str:
"""
Args:
data: The `bytes` buffer containing the string of a string at offset 0
encoding: An encoding value for the encoding paramater of `bytes.decode`
errors: An errors value for the errors parameter of `bytes.decode`
return_truncated: Dictates whether truncated strings should be returned or
if a ValueError should be thrown if a truncated (broken) string was decoded
Returns:
bytes: The decoded string starting at offset of data
This function takes a bytes buffer that contains at a string of unknown
length starting at the first byte, and returns the properly decoded string
It starts by using Python's `bytes.decode` to attempt to decode the entire string
It then finds the termination character (\ufffd or \x00) and splices the string
Finally, it returns this spliced string after its been decoded with the
caller-specified encoding
"""
# this is the standard byte used to replace bad unicode characters
unicode_replacement_char = "\ufffd"
# used to find the terminating byte
termination_re = re.compile(f"{unicode_replacement_char}|\x00")
# run over the entire string, letting Python replace invalid characters
full_decoded_string = data.decode(encoding=encoding, errors="replace")
# stop at the first terminating character or get the whole string if not found
try:
idx = termination_re.search(full_decoded_string).start()
except AttributeError:
if return_truncated:
idx = len(full_decoded_string)
else:
raise ValueError(
"return_truncated set to False and truncated string decoded."
)
# cut at terminating byte, if found
data = bytes(full_decoded_string[:idx], encoding=encoding)
# return with caller-specified encoding and errors
return data.decode(encoding=encoding, errors=errors)
def address_to_string(
context: interfaces.context.ContextInterface,
layer_name: str,
@@ -104,6 +201,7 @@ def address_to_string(
count: int,
errors: str = "replace",
block_size=32,
encoding="utf-8",
) -> str:
"""Reads a null-terminated string from a given specified memory address, processing
it in blocks for efficiency.
@@ -126,18 +224,10 @@ def address_to_string(
raise ValueError("Count must be greater than 0")
layer = context.layers[layer_name]
text = b""
while len(text) < count:
current_block_size = min(count - len(text), block_size)
temp_text = layer.read(address + len(text), current_block_size)
idx = temp_text.find(b"\x00")
if idx != -1:
temp_text = temp_text[:idx]
text += temp_text
break
text += temp_text
return text.decode(errors=errors)
data = gather_contiguous_bytes_from_address(context, layer, address, count)
return bytes_to_decoded_string(data=data, errors=errors, encoding=encoding)
def array_of_pointers(
+7 -2
View File
@@ -32,8 +32,13 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.VersionRequirement(
name="timeliner",
component=timeliner.TimeLinerInterface,
version=(1, 0, 0),
),
requirements.ListRequirement(
name="pid",
@@ -25,8 +25,13 @@ class Boottime(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterface)
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="timeliner",
component=timeliner.TimeLinerInterface,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
]
@@ -60,8 +60,8 @@ class Capabilities(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pids",
@@ -22,8 +22,8 @@ class Check_creds(interfaces.plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
]
@@ -10,7 +10,6 @@ from volatility3.framework import interfaces, renderers, symbols
from volatility3.framework.configuration import requirements
from volatility3.framework.renderers import format_hints
from volatility3.framework.symbols import linux
from volatility3.plugins.linux import lsmod
vollog = logging.getLogger(__name__)
@@ -34,14 +33,16 @@ class Check_idt(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_module_gatherers",
component=linux_utilities_modules.ModuleGatherers,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
),
]
@staticmethod
@@ -82,10 +83,10 @@ class Check_idt(interfaces.plugins.PluginInterface):
vmlinux = self.context.modules[self.config["kernel"]]
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
handlers = linux.LinuxUtilities.generate_kernel_handler_info(
self.context, vmlinux.name, modules
known_modules = linux_utilities_modules.Modules.run_modules_scanners(
context=self.context,
kernel_module_name=self.config["kernel"],
caller_wanted_gatherers=linux_utilities_modules.ModuleGatherers.all_gatherers_identifier,
)
idt_table_size = 256
@@ -134,19 +135,24 @@ class Check_idt(interfaces.plugins.PluginInterface):
module_name = renderers.NotAvailableValue()
symbol_name = renderers.NotAvailableValue()
else:
module_name, symbol_name = (
linux_utilities_modules.Modules.lookup_module_address(
self.context, vmlinux.name, handlers, idt_addr
module_info, symbol_name = (
linux_utilities_modules.Modules.module_lookup_by_address(
self.context, vmlinux.name, known_modules, idt_addr
)
)
if module_info:
module_name = module_info.name
else:
module_name = renderers.NotAvailableValue()
yield (
0,
[
format_hints.Hex(i),
format_hints.Hex(idt_addr),
module_name,
symbol_name,
symbol_name or renderers.NotAvailableValue(),
],
)
@@ -3,15 +3,14 @@
#
import logging
from typing import List, Dict
from typing import List, Dict, Generator
import volatility3.framework.symbols.linux.utilities.modules as linux_utilities_modules
from volatility3.framework import interfaces, renderers, deprecation
from volatility3.framework import interfaces, deprecation
from volatility3.framework.configuration import requirements
from volatility3.framework.interfaces import plugins
from volatility3.framework.objects import utility
from volatility3.framework.renderers import format_hints
from volatility3.framework.symbols.linux import extensions
from volatility3.framework.interfaces import plugins
vollog = logging.getLogger(__name__)
@@ -19,9 +18,31 @@ vollog = logging.getLogger(__name__)
class Check_modules(plugins.PluginInterface):
"""Compares module list to sysfs info, if available"""
_version = (2, 0, 0)
_version = (3, 0, 0)
_required_framework_version = (2, 0, 0)
@classmethod
def compare_kset_and_lsmod(
cls, context: str, vmlinux_name: str
) -> Generator[extensions.module, None, None]:
kset_modules = linux_utilities_modules.Modules.get_kset_modules(
context=context, vmlinux_name=vmlinux_name
)
lsmod_modules = set(
str(utility.array_to_string(modules.name))
for modules in linux_utilities_modules.Modules.list_modules(
context=context, vmlinux_module_name=vmlinux_name
)
)
for mod_name in set(kset_modules.keys()).difference(lsmod_modules):
yield kset_modules[mod_name]
run = linux_utilities_modules.ModuleDisplayPlugin.run
_generator = linux_utilities_modules.ModuleDisplayPlugin.generator
implementation = compare_kset_and_lsmod
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
@@ -31,9 +52,9 @@ class Check_modules(plugins.PluginInterface):
architectures=["Intel32", "Intel64"],
),
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
name="linux_utilities_modules_module_display_plugin",
component=linux_utilities_modules.ModuleDisplayPlugin,
version=(1, 0, 0),
),
]
@@ -41,30 +62,9 @@ class Check_modules(plugins.PluginInterface):
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.get_kset_modules,
removal_date="2025-09-25",
replacement_version=(2, 0, 0),
replacement_version=(3, 0, 0),
)
def get_kset_modules(
cls, context: interfaces.context.ContextInterface, vmlinux_name: str
) -> Dict[str, extensions.module]:
return linux_utilities_modules.Modules.get_kset_modules(context, vmlinux_name)
def _generator(self):
kset_modules = linux_utilities_modules.Modules.get_kset_modules(
self.context, self.config["kernel"]
)
lsmod_modules = set(
str(utility.array_to_string(modules.name))
for modules in linux_utilities_modules.Modules.list_modules(
self.context, self.config["kernel"]
)
)
for mod_name in set(kset_modules.keys()).difference(lsmod_modules):
yield (0, (format_hints.Hex(kset_modules[mod_name]), str(mod_name)))
def run(self):
return renderers.TreeGrid(
[("Module Address", format_hints.Hex), ("Module Name", str)],
self._generator(),
)
@@ -172,8 +172,11 @@ class Check_syscall(plugins.PluginInterface):
count=tblsz,
)
for i, call_addr in enumerate(table):
if not call_addr:
for i in range(len(table)):
try:
call_addr = table[i]
except exceptions.InvalidAddressException:
vollog.debug(f"Failed to get system call table entry at index {i}")
continue
symbols = list(vmlinux.get_symbols_by_absolute_location(call_addr))
+2 -2
View File
@@ -35,8 +35,8 @@ class Elfs(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -29,8 +29,8 @@ class Envars(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -6,86 +6,21 @@ from typing import List, Set, Tuple, Iterable
from volatility3.framework.symbols.linux.utilities import (
modules as linux_utilities_modules,
)
from volatility3.framework import renderers, interfaces, exceptions, deprecation
from volatility3.framework import interfaces, exceptions, deprecation
from volatility3.framework.constants import architectures
from volatility3.framework.renderers import format_hints
from volatility3.framework.configuration import requirements
from volatility3.plugins.linux import lsmod
from volatility3.framework.symbols.linux import extensions
from volatility3.framework.interfaces import plugins
vollog = logging.getLogger(__name__)
class Hidden_modules(interfaces.plugins.PluginInterface):
class Hidden_modules(plugins.PluginInterface):
"""Carves memory to find hidden kernel modules"""
_required_framework_version = (2, 10, 0)
_version = (2, 0, 0)
_version = (3, 0, 0)
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(
name="kernel",
description="Linux kernel",
architectures=architectures.LINUX_ARCHS,
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
),
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
),
]
@staticmethod
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.get_modules_memory_boundaries,
removal_date="2025-09-25",
replacement_version=(2, 0, 0),
)
def get_modules_memory_boundaries(
context: interfaces.context.ContextInterface,
vmlinux_module_name: str,
) -> Tuple[int, int]:
return linux_utilities_modules.Modules.get_modules_memory_boundaries(
context, vmlinux_module_name
)
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.get_module_address_alignment,
removal_date="2025-09-25",
replacement_version=(2, 0, 0),
)
@classmethod
def _get_module_address_alignment(
cls,
context: interfaces.context.ContextInterface,
vmlinux_module_name: str,
) -> int:
"""Obtain the module memory address alignment.
struct module is aligned to the L1 cache line, which is typically 64 bytes for most
common i386/AMD64/ARM64 configurations. In some cases, it can be 128 bytes, but this
will still work.
Args:
context: The context to retrieve required elements (layers, symbol tables) from
vmlinux_module_name: The name of the kernel module on which to operate
Returns:
The struct module alignment
"""
return linux_utilities_modules.get_module_address_alignment(
context, vmlinux_module_name
)
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.get_hidden_modules,
removal_date="2025-09-25",
replacement_version=(2, 0, 0),
)
@classmethod
def get_hidden_modules(
cls,
@@ -120,11 +55,77 @@ class Hidden_modules(interfaces.plugins.PluginInterface):
vmlinux_module_name, known_module_addresses, modules_memory_boundaries
)
run = linux_utilities_modules.ModuleDisplayPlugin.run
_generator = linux_utilities_modules.ModuleDisplayPlugin.generator
implementation = linux_utilities_modules.Modules.list_modules
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(
name="kernel",
description="Linux kernel",
architectures=architectures.LINUX_ARCHS,
),
requirements.VersionRequirement(
name="linux_utilities_modules_module_display_plugin",
component=linux_utilities_modules.ModuleDisplayPlugin,
version=(1, 0, 0),
),
]
@staticmethod
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.get_modules_memory_boundaries,
removal_date="2025-09-25",
replacement_version=(3, 0, 0),
)
def get_modules_memory_boundaries(
context: interfaces.context.ContextInterface,
vmlinux_module_name: str,
) -> Tuple[int, int]:
return linux_utilities_modules.Modules.get_modules_memory_boundaries(
context, vmlinux_module_name
)
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.get_module_address_alignment,
removal_date="2025-09-25",
replacement_version=(3, 0, 0),
)
@classmethod
def _get_module_address_alignment(
cls,
context: interfaces.context.ContextInterface,
vmlinux_module_name: str,
) -> int:
"""Obtain the module memory address alignment.
struct module is aligned to the L1 cache line, which is typically 64 bytes for most
common i386/AMD64/ARM64 configurations. In some cases, it can be 128 bytes, but this
will still work.
Args:
context: The context to retrieve required elements (layers, symbol tables) from
vmlinux_module_name: The name of the kernel module on which to operate
Returns:
The struct module alignment
"""
return linux_utilities_modules.get_module_address_alignment(
context, vmlinux_module_name
)
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.get_hidden_modules,
removal_date="2025-09-25",
replacement_version=(3, 0, 0),
)
@staticmethod
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.validate_alignment_patterns,
removal_date="2025-09-25",
replacement_version=(2, 0, 0),
replacement_version=(3, 0, 0),
)
def _validate_alignment_patterns(
addresses: Iterable[int],
@@ -163,42 +164,35 @@ class Hidden_modules(interfaces.plugins.PluginInterface):
known_module_addresses = {
vmlinux_layer.canonicalize(module.vol.offset)
for module in lsmod.Lsmod.list_modules(context, vmlinux_module_name)
for module in linux_utilities_modules.Modules.list_modules(
context, vmlinux_module_name
)
}
return known_module_addresses
def _generator(self):
vmlinux_module_name = self.config["kernel"]
known_module_addresses = self.get_lsmod_module_addresses(
self.context, vmlinux_module_name
)
modules_memory_boundaries = (
linux_utilities_modules.Modules.get_modules_memory_boundaries(
self.context, vmlinux_module_name
)
)
for module in linux_utilities_modules.Modules.get_hidden_modules(
self.context,
vmlinux_module_name,
known_module_addresses,
modules_memory_boundaries,
):
module_addr = module.vol.offset
module_name = module.get_name() or renderers.NotAvailableValue()
fields = (format_hints.Hex(module_addr), module_name)
yield (0, fields)
def run(self):
if self.context.symbol_space.verify_table_versions(
@classmethod
def find_hidden_modules(
cls, context, vmlinux_module_name: str
) -> extensions.module:
if context.symbol_space.verify_table_versions(
"dwarf2json", lambda version, _: (not version) or version < (0, 8, 0)
):
raise exceptions.SymbolSpaceError(
"Invalid symbol table, please ensure the ISF table produced by dwarf2json was created with version 0.8.0 or later"
)
headers = [
("Address", format_hints.Hex),
("Name", str),
]
return renderers.TreeGrid(headers, self._generator())
known_module_addresses = cls.get_lsmod_module_addresses(
context, vmlinux_module_name
)
modules_memory_boundaries = (
linux_utilities_modules.Modules.get_modules_memory_boundaries(
context, vmlinux_module_name
)
)
yield from linux_utilities_modules.Modules.get_hidden_modules(
context,
vmlinux_module_name,
known_module_addresses,
modules_memory_boundaries,
)
+12 -3
View File
@@ -59,7 +59,7 @@ class IOMem(interfaces.plugins.PluginInterface):
f"Unable to create resource object at {resource_offset:#x}. This resource, "
"its sibling, and any of it's children and will be missing from the output."
)
return None
return
# get name with protection against smear as following a pointer
try:
@@ -71,6 +71,15 @@ class IOMem(interfaces.plugins.PluginInterface):
)
name = renderers.UnreadableValue()
try:
start = resource.start
end = resource.end
except exceptions.InvalidAddressException:
vollog.warning(
f"Unable to follow pointer to start and end for resource object at {resource_offset:#x}. Skipping entry."
)
return
# mark this resource as seen in the seen set. Normally this should not be needed but will protect
# against possible infinite loops. Warn the user if an infinite loop would have happened.
if resource_offset in seen:
@@ -79,12 +88,12 @@ class IOMem(interfaces.plugins.PluginInterface):
"this should not normally occur. No further results from related resources will be "
"displayed to protect against infinite loops."
)
return None
return
else:
seen.add(resource_offset)
# yield information on this resource
yield depth, (name, resource.start, resource.end)
yield depth, (name, start, end)
# process child resource if this exists
if resource.child != 0:
@@ -73,6 +73,9 @@ class Kallsyms(plugins.PluginInterface):
# resulting in incorrect values. Unfortunately, there isn't much that can be done
# in such cases.
# See comments on .init.scratch in arch/x86/kernel/vmlinux.lds.S for details
if not kassymbol or not kassymbol.size:
return renderers.NotAvailableValue()
return kassymbol.size if kassymbol.size >= 0 else renderers.NotAvailableValue()
def _generator(self):
@@ -95,6 +98,7 @@ class Kallsyms(plugins.PluginInterface):
include_core = include_modules = include_ftrace = include_bpf = True
symbol_generators = []
if include_core:
symbol_generators.append(kas.get_core_symbols())
if include_modules:
@@ -106,17 +110,25 @@ class Kallsyms(plugins.PluginInterface):
for symbols_generator in symbol_generators:
for kassymbol in symbols_generator:
if not kassymbol:
continue
# Symbol sizes are calculated using the address of the next non-aliased
# symbol or the end of the kernel text area _end/_etext. However, some kernel
# symbols are located beyond that area, which causes this method to fail for
# the last symbol, resulting in a negative size.
# See comments on .init.scratch in arch/x86/kernel/vmlinux.lds.S for details
symbol_size = self._get_symbol_size(kassymbol)
if kassymbol.exported is None:
exported = renderers.NotAvailableValue()
else:
exported = kassymbol.exported
fields = (
format_hints.Hex(kassymbol.address),
kassymbol.type,
kassymbol.type or renderers.NotAvailableValue(),
symbol_size,
kassymbol.exported,
exported,
kassymbol.subsystem,
kassymbol.module_name,
kassymbol.name,
@@ -9,7 +9,6 @@ from volatility3.framework import interfaces, renderers, exceptions
from volatility3.framework.configuration import requirements
from volatility3.framework.renderers import format_hints
from volatility3.framework.symbols import linux
from volatility3.plugins.linux import lsmod
vollog = logging.getLogger(__name__)
@@ -30,10 +29,12 @@ class Keyboard_notifiers(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="linux_utilities_module_gatherers",
component=linux_utilities_modules.ModuleGatherers,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 0, 0)
@@ -43,12 +44,6 @@ class Keyboard_notifiers(interfaces.plugins.PluginInterface):
def _generator(self):
vmlinux = self.context.modules[self.config["kernel"]]
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
handlers = linux.LinuxUtilities.generate_kernel_handler_info(
self.context, vmlinux.name, modules
)
try:
knl_addr = vmlinux.object_from_symbol("keyboard_notifier_list")
except exceptions.SymbolError:
@@ -65,6 +60,12 @@ class Keyboard_notifiers(interfaces.plugins.PluginInterface):
vollog.error("The head of the keyboard notifier list is paged out.")
return
known_modules = linux_utilities_modules.Modules.run_modules_scanners(
context=self.context,
kernel_module_name=self.config["kernel"],
caller_wanted_gatherers=linux_utilities_modules.ModuleGatherers.all_gatherers_identifier,
)
knl = vmlinux.object(
object_type="atomic_notifier_head",
offset=knl_addr.vol.offset,
@@ -76,13 +77,25 @@ class Keyboard_notifiers(interfaces.plugins.PluginInterface):
):
call_addr = call_back.notifier_call
module_name, symbol_name = (
linux_utilities_modules.Modules.lookup_module_address(
self.context, vmlinux.name, handlers, call_addr
module_info, symbol_name = (
linux_utilities_modules.Modules.module_lookup_by_address(
self.context, vmlinux.name, known_modules, call_addr
)
)
yield (0, [format_hints.Hex(call_addr), module_name, symbol_name])
if module_info:
module_name = module_info.name
else:
module_name = renderers.NotAvailableValue()
yield (
0,
[
format_hints.Hex(call_addr),
module_name,
symbol_name or renderers.NotAvailableValue(),
],
)
def run(self):
return renderers.TreeGrid(
+27 -23
View File
@@ -5,14 +5,14 @@ import logging
from typing import List
import volatility3.framework.symbols.linux.utilities.modules as linux_utilities_modules
from volatility3.framework import constants, exceptions, interfaces, renderers
from volatility3.framework import exceptions, interfaces, renderers
from volatility3.framework.configuration import requirements
from volatility3.framework.interfaces import plugins
from volatility3.framework.renderers import format_hints
from volatility3.framework.symbols import linux
from volatility3.framework.constants import architectures
from volatility3.framework.objects import utility
from volatility3.plugins.linux import pslist, lsmod
from volatility3.plugins.linux import pslist
vollog = logging.getLogger(__name__)
@@ -34,36 +34,37 @@ class Kthreads(plugins.PluginInterface):
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_module_gatherers",
component=linux_utilities_modules.ModuleGatherers,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 1, 0)
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
]
def _generator(self):
vmlinux = self.context.modules[self.config["kernel"]]
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
handlers = linux.LinuxUtilities.generate_kernel_handler_info(
self.context, vmlinux.name, modules
)
kthread_type = vmlinux.get_type(
vmlinux.symbol_table_name + constants.BANG + "kthread"
)
kthread_type = vmlinux.get_type("kthread")
if not kthread_type.has_member("threadfn"):
raise exceptions.VolatilityException(
"Unsupported kthread implementation. This plugin only works with kernels >= 5.8"
)
known_modules = linux_utilities_modules.Modules.run_modules_scanners(
context=self.context,
kernel_module_name=self.config["kernel"],
caller_wanted_gatherers=linux_utilities_modules.ModuleGatherers.all_gatherers_identifier,
)
for task in pslist.PsList.list_tasks(
self.context, vmlinux.name, include_threads=True
):
@@ -86,9 +87,7 @@ class Kthreads(plugins.PluginInterface):
if not (threadfn and threadfn.is_readable()):
continue
task_name = utility.array_to_string(task.comm)
thread_name = task_name
thread_name = utility.array_to_string(task.comm)
# kernels >= 5.17 in d6986ce24fc00b0638bd29efe8fb7ba7619ed2aa full_name was added to kthread
if kthread.has_member("full_name"):
@@ -101,18 +100,23 @@ class Kthreads(plugins.PluginInterface):
f"full_name pointer for thread at {kthread.vol.offset:#x} is paged out."
)
module_name, symbol_name = (
linux_utilities_modules.Modules.lookup_module_address(
self.context, vmlinux.name, handlers, threadfn
module_info, symbol_name = (
linux_utilities_modules.Modules.module_lookup_by_address(
self.context, vmlinux.name, known_modules, threadfn
)
)
if module_info:
module_name = module_info.name
else:
module_name = renderers.NotAvailableValue()
fields = [
task.pid,
thread_name,
format_hints.Hex(threadfn),
module_name,
symbol_name,
symbol_name or renderers.NotAvailableValue(),
]
yield 0, fields
@@ -31,8 +31,8 @@ class LibraryList(interfaces.plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pids",
+13 -28
View File
@@ -7,11 +7,9 @@ import logging
from typing import List, Iterable
import volatility3.framework.symbols.linux.utilities.modules as linux_utilities_modules
from volatility3.framework import exceptions, renderers, interfaces, deprecation
from volatility3.framework import interfaces, deprecation
from volatility3.framework.configuration import requirements
from volatility3.framework.interfaces import plugins
from volatility3.framework.objects import utility
from volatility3.framework.renderers import format_hints
vollog = logging.getLogger(__name__)
@@ -20,7 +18,11 @@ class Lsmod(plugins.PluginInterface):
"""Lists loaded kernel modules."""
_required_framework_version = (2, 0, 0)
_version = (2, 0, 0)
_version = (3, 0, 0)
run = linux_utilities_modules.ModuleDisplayPlugin.run
_generator = linux_utilities_modules.ModuleDisplayPlugin.generator
implementation = linux_utilities_modules.Modules.list_modules
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
@@ -33,14 +35,19 @@ class Lsmod(plugins.PluginInterface):
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_modules_module_display_plugin",
component=linux_utilities_modules.ModuleDisplayPlugin,
version=(1, 0, 0),
),
]
@classmethod
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.list_modules,
replacement_version=(2, 0, 0),
replacement_version=(3, 0, 0),
removal_date="2025-09-25",
)
def list_modules(
@@ -49,25 +56,3 @@ class Lsmod(plugins.PluginInterface):
return linux_utilities_modules.Modules.list_modules(
context, vmlinux_module_name
)
def _generator(self):
try:
for module in linux_utilities_modules.Modules.list_modules(
self.context, self.config["kernel"]
):
mod_size = module.get_init_size() + module.get_core_size()
mod_name = utility.array_to_string(module.name)
yield 0, (format_hints.Hex(module.vol.offset), mod_name, mod_size)
except exceptions.SymbolError:
vollog.warning(
"The required symbol 'module' is not present in symbol table. Please check that kernel modules are enabled for the system under analysis."
)
def run(self):
return renderers.TreeGrid(
[("Offset", format_hints.Hex), ("Name", str), ("Size", int)],
self._generator(),
)
+7 -2
View File
@@ -120,8 +120,13 @@ class Lsof(plugins.PluginInterface, timeliner.TimeLinerInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.VersionRequirement(
name="timeliner",
component=timeliner.TimeLinerInterface,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 0, 0)
@@ -28,8 +28,8 @@ class Malfind(interfaces.plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
+40 -18
View File
@@ -34,7 +34,22 @@ spot modules presence and taints."""
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_module_gatherer_lsmod",
component=linux_utilities_modules.ModuleGathererLsmod,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_module_gatherer_sysfs",
component=linux_utilities_modules.ModuleGathererSysFs,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_module_gatherer_scanner",
component=linux_utilities_modules.ModuleGathererScanner,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linux-tainting", component=tainting.Tainting, version=(1, 0, 0)
@@ -50,7 +65,7 @@ spot modules presence and taints."""
@classmethod
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.flatten_run_modules_results,
replacement_version=(2, 0, 0),
replacement_version=(3, 0, 0),
removal_date="2025-09-25",
)
def flatten_run_modules_results(
@@ -73,7 +88,7 @@ spot modules presence and taints."""
@classmethod
@deprecation.deprecated_method(
replacement=linux_utilities_modules.Modules.run_modules_scanners,
replacement_version=(2, 0, 0),
replacement_version=(3, 0, 0),
removal_date="2025-09-25",
)
def run_modules_scanners(
@@ -89,35 +104,42 @@ spot modules presence and taints."""
)
def _generator(self):
kernel_name = self.config["kernel"]
kernel = self.context.modules[self.config["kernel"]]
kernel = self.context.modules[kernel_name]
wanted_gatherers = [
linux_utilities_modules.ModuleGathererLsmod,
linux_utilities_modules.ModuleGathererSysFs,
linux_utilities_modules.ModuleGathererScanner,
]
run_results = linux_utilities_modules.Modules.run_modules_scanners(
self.context, kernel_name, flatten=False
context=self.context,
kernel_module_name=self.config["kernel"],
caller_wanted_gatherers=wanted_gatherers,
flatten=False,
)
aggregated_modules = {}
# We want to be explicit on the plugins results we are interested in
for plugin_name in ["lsmod", "check_modules", "hidden_modules"]:
for gatherer in wanted_gatherers:
# Iterate over each recovered module
for mod_info in run_results[plugin_name]:
for mod_info in run_results[gatherer.name]:
# Use offsets as unique keys, whether a module
# appears in many plugin runs or not
if aggregated_modules.get(mod_info.offset, None) is not None:
# Append the plugin to the list of originating plugins
aggregated_modules[mod_info.offset].append(plugin_name)
aggregated_modules[mod_info.offset].append(gatherer.name)
else:
aggregated_modules[mod_info.offset] = [plugin_name]
aggregated_modules[mod_info.offset] = [gatherer.name]
for module_offset, originating_plugins in aggregated_modules.items():
# Tainting parsing capabilities applied to the module
for module_offset, gatherers in aggregated_modules.items():
module = kernel.object("module", offset=module_offset, absolute=True)
# Tainting parsing capabilities applied to the module
if self.config.get("plain_taints"):
taints = tainting.Tainting.get_taints_as_plain_string(
self.context,
kernel_name,
self.config["kernel"],
module.taints,
True,
)
@@ -125,7 +147,7 @@ spot modules presence and taints."""
taints = ",".join(
tainting.Tainting.get_taints_parsed(
self.context,
kernel_name,
self.config["kernel"],
module.taints,
True,
)
@@ -136,9 +158,9 @@ spot modules presence and taints."""
(
module.get_name() or NotAvailableValue(),
format_hints.Hex(module_offset),
"lsmod" in originating_plugins,
"check_modules" in originating_plugins,
"hidden_modules" in originating_plugins,
linux_utilities_modules.ModuleGathererLsmod.name in gatherers,
linux_utilities_modules.ModuleGathererSysFs.name in gatherers,
linux_utilities_modules.ModuleGathererScanner.name in gatherers,
taints or NotAvailableValue(),
),
)
@@ -149,7 +171,7 @@ spot modules presence and taints."""
("Address", format_hints.Hex),
("In procfs", bool),
("In sysfs", bool),
("Hidden", bool),
("In scan", bool),
("Taints", str),
]
@@ -46,8 +46,8 @@ class MountInfo(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 1, 0)
@@ -13,12 +13,11 @@ from volatility3.framework import (
interfaces,
renderers,
exceptions,
deprecation,
)
from volatility3.framework.renderers import format_hints
from volatility3.framework.configuration import requirements
from volatility3.framework.symbols import linux
from volatility3.framework.symbols.linux import network
from volatility3.plugins.linux import lsmod
vollog = logging.getLogger(__name__)
@@ -82,22 +81,18 @@ class AbstractNetfilter(ABC):
self.ptr_size = self.vmlinux.get_type("pointer").size
self.list_head_size = self.vmlinux.get_type("list_head").size
lsmod_required_version = Netfilter._required_lsmod_version
lsmod_current_version = lsmod.Lsmod.version
linuxutils_modulegatherers_required_version = (
Netfilter._required_linuxutils_gatherers_version
)
linuxutils_modulegatherers_current_version = (
linux_utilities_modules.ModuleGatherers.version
)
if not requirements.VersionRequirement.matches_required(
lsmod_required_version, lsmod_current_version
linuxutils_modulegatherers_required_version,
linuxutils_modulegatherers_current_version,
):
raise exceptions.PluginRequirementException(
f"linux.lsmod.Lsmod version not suitable: required {lsmod_required_version} found {lsmod_current_version}"
)
linuxutils_required_version = Netfilter._required_linuxutils_version
linuxutils_current_version = linux.LinuxUtilities.version
if not requirements.VersionRequirement.matches_required(
linuxutils_required_version, linuxutils_current_version
):
raise exceptions.PluginRequirementException(
f"linux.LinuxUtilities version not suitable: required {linuxutils_required_version} found {linuxutils_current_version}"
f"linux_utilities_modules.ModuleGatherer version not suitable: required {linuxutils_modulegatherers_required_version} found {linuxutils_modulegatherers_current_version}"
)
linux_net_required_version = Netfilter._required_linuxnet_version
@@ -123,12 +118,13 @@ class AbstractNetfilter(ABC):
f"linux_utilities_modules.Modules version not suitable: required {linux_utilities_modules_required_version} found {linux_utilities_modules_current_version}"
)
symbol_table = self._context.symbol_space[self.vmlinux.symbol_table_name]
symbol_table = context.symbol_space[self.vmlinux.symbol_table_name]
network.NetSymbols.apply(symbol_table)
modules = lsmod.Lsmod.list_modules(context, kernel_module_name)
self.handlers = linux.LinuxUtilities.generate_kernel_handler_info(
context, kernel_module_name, modules
self.handlers = linux_utilities_modules.Modules.run_modules_scanners(
context=context,
kernel_module_name=kernel_module_name,
caller_wanted_gatherers=linux_utilities_modules.ModuleGatherers.all_gatherers_identifier,
)
@classmethod
@@ -217,10 +213,17 @@ class AbstractNetfilter(ABC):
priority = int(hook_ops.priority)
hook_ops_hook = hook_ops.hook
module_name = self.get_module_name_for_address(hook_ops_hook)
hooked = module_name is None
module_info, symbol_name = (
linux_utilities_modules.Modules.module_lookup_by_address(
self._context,
self.vmlinux.name,
self.handlers,
hook_ops_hook,
)
)
hooked = module_info is None
yield netns, proto_name, hook_name, priority, hook_ops_hook, module_name, hooked
yield netns, proto_name, hook_name, priority, hook_ops_hook, module_info, symbol_name, hooked
@classmethod
@abstractmethod
@@ -300,6 +303,10 @@ class AbstractNetfilter(ABC):
# in other parts of the kernel source code.
return ("IPV4", "ARP", "BRIDGE", "IPV6", "DECNET")
@deprecation.method_being_removed(
removal_date="2025-09-25",
message="Callers to this method should adapt `linux_utilities_modules.Modules.run_module_scanners`",
)
def get_module_name_for_address(self, addr) -> str:
"""Helper to obtain the module and symbol name in the format needed for the
output of this plugin.
@@ -724,11 +731,10 @@ class Netfilter(interfaces.plugins.PluginInterface):
_required_framework_version = (2, 22, 0)
_version = (1, 1, 1)
_version = (2, 0, 0)
_required_linux_utilities_modules_version = (2, 0, 0)
_required_linuxutils_version = (2, 1, 0)
_required_lsmod_version = (2, 0, 0)
_required_linux_utilities_modules_version = (3, 0, 0)
_required_linuxutils_gatherers_version = (1, 0, 0)
_required_linuxnet_version = (1, 0, 0)
@classmethod
@@ -740,17 +746,9 @@ class Netfilter(interfaces.plugins.PluginInterface):
architectures=["Intel32", "Intel64"],
),
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=cls._required_linux_utilities_modules_version,
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=cls._required_lsmod_version
),
requirements.VersionRequirement(
name="linuxutils",
component=linux.LinuxUtilities,
version=cls._required_linuxutils_version,
name="linux_utilities_module_gatherers",
component=linux_utilities_modules.ModuleGatherers,
version=cls._required_linuxutils_gatherers_version,
),
requirements.VersionRequirement(
name="linuxnet",
@@ -766,16 +764,24 @@ class Netfilter(interfaces.plugins.PluginInterface):
hook_name,
priority,
hook_func,
module_name,
module_info,
symbol_name,
hooked,
) = fields
if module_info:
module_name = module_info.name
else:
module_name = renderers.NotAvailableValue()
return (
netns,
proto_name,
hook_name,
priority,
format_hints.Hex(hook_func),
module_name or renderers.NotAvailableValue(),
module_name,
symbol_name or renderers.NotAvailableValue(),
str(hooked),
)
@@ -794,6 +800,7 @@ class Netfilter(interfaces.plugins.PluginInterface):
("Priority", int),
("Handler", format_hints.Hex),
("Module", str),
("Symbol", str),
("Is Hooked", str),
]
return renderers.TreeGrid(headers, self._generator())
@@ -126,8 +126,13 @@ class Files(plugins.PluginInterface, timeliner.TimeLinerInterface):
description="Linux kernel",
architectures=architectures.LINUX_ARCHS,
),
requirements.PluginRequirement(
name="mountinfo", plugin=mountinfo.MountInfo, version=(1, 2, 0)
requirements.VersionRequirement(
name="mountinfo", component=mountinfo.MountInfo, version=(1, 2, 0)
),
requirements.VersionRequirement(
name="timeliner",
component=timeliner.TimeLinerInterface,
version=(1, 0, 0),
),
requirements.ListRequirement(
name="type",
@@ -431,8 +436,8 @@ class InodePages(plugins.PluginInterface):
description="Linux kernel",
architectures=architectures.LINUX_ARCHS,
),
requirements.PluginRequirement(
name="files", plugin=Files, version=(1, 0, 0)
requirements.VersionRequirement(
name="files", component=Files, version=(1, 0, 0)
),
requirements.StringRequirement(
name="find",
@@ -650,11 +655,11 @@ class RecoverFs(plugins.PluginInterface):
description="Linux kernel",
architectures=architectures.LINUX_ARCHS,
),
requirements.PluginRequirement(
name="files", plugin=Files, version=(1, 1, 0)
requirements.VersionRequirement(
name="files", component=Files, version=(1, 1, 0)
),
requirements.PluginRequirement(
name="inodepages", plugin=InodePages, version=(3, 0, 0)
requirements.VersionRequirement(
name="inodepages", component=InodePages, version=(3, 0, 0)
),
requirements.BooleanRequirement(
name="tmpfs_only",
@@ -29,8 +29,8 @@ class PIDHashTable(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 1, 0)
+2 -2
View File
@@ -34,8 +34,8 @@ class Maps(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
+2 -2
View File
@@ -26,8 +26,8 @@ class PsAux(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -45,8 +45,8 @@ class PsCallStack(plugins.PluginInterface):
requirements.VersionRequirement(
name="Kallsyms", component=kallsyms.Kallsyms, version=(1, 0, 0)
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -118,9 +118,15 @@ class PsCallStack(plugins.PluginInterface):
current_sp = rsp_start
idx = 0
while current_sp < task_top_of_stack:
stack_value_bytes = task_layer.read(current_sp, pointer_size)
try:
stack_value_bytes = task_layer.read(current_sp, pointer_size)
except exceptions.InvalidAddressException:
break
stack_value = int.from_bytes(stack_value_bytes, byteorder=byte_order)
if not stack_value:
idx += 1
current_sp += pointer_size
continue
kassymbol = kas.lookup_address(stack_value)
sp_address = current_sp & vmlinux_layer.address_mask
stack_value &= vmlinux_layer.address_mask
@@ -44,8 +44,8 @@ class PsList(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="elfs", plugin=elfs.Elfs, version=(2, 0, 0)
requirements.VersionRequirement(
name="elfs", component=elfs.Elfs, version=(2, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -53,6 +53,11 @@ class PsList(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterface):
element_type=int,
optional=True,
),
requirements.VersionRequirement(
name="timeliner",
component=timeliner.TimeLinerInterface,
version=(1, 0, 0),
),
requirements.BooleanRequirement(
name="threads",
description="Include user threads",
@@ -38,8 +38,8 @@ class PsScan(interfaces.plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
]
@@ -27,8 +27,8 @@ class PsTree(interfaces.plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -29,8 +29,8 @@ class Ptrace(plugins.PluginInterface):
description="Linux kernel",
architectures=architectures.LINUX_ARCHS,
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
]
@@ -463,11 +463,11 @@ class Sockstat(plugins.PluginInterface):
requirements.VersionRequirement(
name="SockHandlers", component=SockHandlers, version=(4, 0, 0)
),
requirements.PluginRequirement(
name="lsof", plugin=lsof.Lsof, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsof", component=lsof.Lsof, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 0, 0)
@@ -5,7 +5,7 @@
# Public researches: https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Fixing-A-Memory-Forensics-Blind-Spot-Linux-Kernel-Tracing-wp.pdf
import logging
from typing import Dict, List, Generator
from typing import List, Generator
from enum import Enum
from dataclasses import dataclass
@@ -65,7 +65,7 @@ class CheckFtrace(interfaces.plugins.PluginInterface):
Investigate the ftrace infrastructure to uncover kernel attached callbacks, which can be leveraged
to hook kernel functions and modify their behaviour."""
_version = (3, 0, 0)
_version = (4, 0, 0)
_required_framework_version = (2, 19, 0)
@classmethod
@@ -79,7 +79,12 @@ class CheckFtrace(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_module_gatherers",
component=linux_utilities_modules.ModuleGatherers,
version=(1, 0, 0),
),
requirements.BooleanRequirement(
name="show_ftrace_flags",
@@ -127,9 +132,8 @@ class CheckFtrace(interfaces.plugins.PluginInterface):
cls,
context: interfaces.context.ContextInterface,
kernel_module_name: str,
known_modules: Dict[str, List[linux_utilities_modules.Modules.ModuleInfo]],
known_modules: List[linux_utilities_modules.ModuleInfo],
ftrace_ops: interfaces.objects.ObjectInterface,
run_hidden_modules: bool = True,
) -> Generator[ParsedFtraceOps, None, None]:
"""Parse an ftrace_ops struct to highlight ftrace kernel hooking.
Iterates over embedded ftrace_func_entry entries, which point to hooked memory areas.
@@ -137,8 +141,6 @@ class CheckFtrace(interfaces.plugins.PluginInterface):
Args:
known_modules: A dict of known modules, used to locate callbacks origin. Typically obtained through run_modules_scanners().
ftrace_ops: The ftrace_ops struct to parse
run_hidden_modules: Whether to run the hidden_modules plugin or not. Note: it won't be run, even if specified, \
if the "hidden_modules" key is present in known_modules.
Yields:
An iterable of ParsedFtraceOps dataclasses, containing a selection of useful fields (callback, hook, module) related to an ftrace_ops struct
@@ -223,7 +225,9 @@ class CheckFtrace(interfaces.plugins.PluginInterface):
return
known_modules = linux_utilities_modules.Modules.run_modules_scanners(
self.context, kernel_name, run_hidden_modules=True
context=self.context,
kernel_module_name=self.config["kernel"],
caller_wanted_gatherers=linux_utilities_modules.ModuleGatherers.all_gatherers_identifier,
)
for ftrace_ops in self.iterate_ftrace_ops_list(self.context, kernel_name):
@@ -0,0 +1,145 @@
# This file is Copyright 2025 Volatility Foundation and licensed under the Volatility Software License 1.0
# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0
#
import logging
from typing import List, Tuple, Generator, Optional
from volatility3.framework import renderers, interfaces, constants, exceptions
from volatility3.framework.renderers import format_hints
from volatility3.framework.configuration import requirements
from volatility3.framework.interfaces import plugins
from volatility3.framework.objects import utility
from volatility3.plugins.linux import pslist
vollog = logging.getLogger(__name__)
class PerfEvents(plugins.PluginInterface):
"""Lists performance events for each process."""
_required_framework_version = (2, 0, 0)
_version = (1, 0, 0)
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.ModuleRequirement(
name="kernel",
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
),
]
@classmethod
def list_perf_events(cls, context, vmlinux_module_name: str) -> Generator[
Tuple[
interfaces.objects.ObjectInterface,
interfaces.objects.ObjectInterface,
Optional[str],
Optional[str],
Optional[str],
Optional[int],
],
None,
None,
]:
"""
Walks the `perf_event_list` of each `task_struct` and reports valid event structures found
This plugin is one of several to detect eBPF based malware
Args:
context:
vmlinux_module_name:
Returns:
A tuple of the task struct, performance event object, event name, program name, full name, and program address
"""
vmlinux = context.modules[vmlinux_module_name]
if not vmlinux.has_type("perf_event") or not vmlinux.get_type(
"perf_event"
).has_member("owner_entry"):
vollog.warning(
"This kernel does not have performance events enabled (CONFIG_PERF_EVENTS). Cannot proceed."
)
return
for task in pslist.PsList.list_tasks(
context, vmlinux_module_name, include_threads=True
):
# walk the list of perf_event entries for this process
for event in task.perf_event_list.to_list(
vmlinux.symbol_table_name + constants.BANG + "perf_event", "owner_entry"
):
# if the names are smeared then bail
try:
event_name = utility.pointer_to_string(event.pmu.name, count=64)
try:
full_name = utility.array_to_string(
event.prog.aux.ksym.name, count=512
)
except AttributeError:
full_name = None
program_name = utility.array_to_string(event.prog.aux.name)
except exceptions.InvalidAddressException:
continue
# if the kernel has the prog member then ensure it is not 0
if hasattr(event, "prog"):
program_address = event.prog
if program_address == 0:
continue
else:
program_address = None
yield task, event_name, program_name, full_name, program_address
def _generator(self):
for (
task,
event_name,
program_name,
full_name,
program_address,
) in self.list_perf_events(self.context, self.config["kernel"]):
task_name = utility.array_to_string(task.comm)
# We at least need one useful string...
if event_name is None and program_name is None and full_name is None:
continue
if program_address is not None:
program_address = format_hints.Hex(program_address)
else:
program_address = renderers.NotAvailableValue()
yield (
0,
(
task.pid,
task_name,
event_name or renderers.NotAvailableValue(),
program_name or renderers.NotAvailableValue(),
full_name or renderers.NotAvailableValue(),
program_address,
),
)
def run(self) -> renderers.TreeGrid:
return renderers.TreeGrid(
[
("PID", int),
("Process", str),
("Event", str),
("Short Program Name", str),
("Full Name", str),
("Address", format_hints.Hex),
],
self._generator(),
)
@@ -5,7 +5,7 @@
# Public researches: https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Fixing-A-Memory-Forensics-Blind-Spot-Linux-Kernel-Tracing-wp.pdf
import logging
from typing import Dict, Iterable, List, Optional
from typing import Iterable, List, Optional
from dataclasses import dataclass
import volatility3.framework.symbols.linux.utilities.modules as linux_utilities_modules
@@ -38,7 +38,7 @@ class CheckTracepoints(interfaces.plugins.PluginInterface):
Investigate the tracepoints subsystem to uncover kernel attached probes, which can be leveraged
to hook kernel functions and modify their behaviour."""
_version = (1, 0, 0)
_version = (2, 0, 0)
_required_framework_version = (2, 19, 0)
@classmethod
@@ -52,7 +52,12 @@ class CheckTracepoints(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.VersionRequirement(
name="linux_utilities_module_gatherers",
component=linux_utilities_modules.ModuleGatherers,
version=(1, 0, 0),
),
]
@@ -96,7 +101,7 @@ class CheckTracepoints(interfaces.plugins.PluginInterface):
cls,
context: interfaces.context.ContextInterface,
kernel_module_name: str,
known_modules: Dict[str, List[linux_utilities_modules.Modules.ModuleInfo]],
known_modules: List[linux_utilities_modules.ModuleInfo],
tracepoint: interfaces.objects.ObjectInterface,
run_hidden_modules: bool = True,
) -> Optional[Iterable[ParsedTracepointFunc]]:
@@ -229,7 +234,9 @@ class CheckTracepoints(interfaces.plugins.PluginInterface):
return
known_modules = linux_utilities_modules.Modules.run_modules_scanners(
self.context, kernel_name, run_hidden_modules=False
context=self.context,
kernel_module_name=self.config["kernel"],
caller_wanted_gatherers=linux_utilities_modules.ModuleGatherers.all_gatherers_identifier,
)
tracepoints = self.iterate_tracepoints_array(self.context, kernel_name)
@@ -12,7 +12,6 @@ from volatility3.framework.interfaces import plugins
from volatility3.framework.objects import utility
from volatility3.framework.renderers import format_hints
from volatility3.framework.symbols import linux
from volatility3.plugins.linux import lsmod
vollog = logging.getLogger(__name__)
@@ -33,10 +32,12 @@ class tty_check(plugins.PluginInterface):
requirements.VersionRequirement(
name="linux_utilities_modules",
component=linux_utilities_modules.Modules,
version=(2, 0, 0),
version=(3, 0, 0),
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="linux_utilities_module_gatherers",
component=linux_utilities_modules.ModuleGatherers,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="linuxutils", component=linux.LinuxUtilities, version=(2, 0, 0)
@@ -46,12 +47,6 @@ class tty_check(plugins.PluginInterface):
def _generator(self):
vmlinux = self.context.modules[self.config["kernel"]]
modules = lsmod.Lsmod.list_modules(self.context, vmlinux.name)
handlers = linux.LinuxUtilities.generate_kernel_handler_info(
self.context, vmlinux.name, modules
)
try:
tty_drivers = vmlinux.object_from_symbol("tty_drivers").cast("list_head")
except exceptions.SymbolError:
@@ -64,6 +59,12 @@ class tty_check(plugins.PluginInterface):
"This means you are either analyzing an unsupported kernel version or that your symbol table is corrupt."
)
known_modules = linux_utilities_modules.Modules.run_modules_scanners(
context=self.context,
kernel_module_name=self.config["kernel"],
caller_wanted_gatherers=linux_utilities_modules.ModuleGatherers.all_gatherers_identifier,
)
for tty in tty_drivers.to_list(
vmlinux.symbol_table_name + constants.BANG + "tty_driver", "tty_drivers"
):
@@ -87,13 +88,23 @@ class tty_check(plugins.PluginInterface):
except exceptions.InvalidAddressException:
continue
module_name, symbol_name = (
linux_utilities_modules.Modules.lookup_module_address(
self.context, vmlinux.name, handlers, recv_buf
module_info, symbol_name = (
linux_utilities_modules.Modules.module_lookup_by_address(
self.context, vmlinux.name, known_modules, recv_buf
)
)
yield (0, (name, format_hints.Hex(recv_buf), module_name, symbol_name))
if module_info:
module_name = module_info.name
else:
module_name = renderers.NotAvailableValue()
yield 0, (
name,
format_hints.Hex(recv_buf),
module_name,
symbol_name or renderers.NotAvailableValue(),
)
def run(self):
return renderers.TreeGrid(
@@ -34,8 +34,8 @@ class VmaRegExScan(plugins.PluginInterface):
description="Linux kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -30,11 +30,11 @@ class VmaYaraScan(interfaces.plugins.PluginInterface):
description="Process IDs to include (all other processes are excluded)",
optional=True,
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(4, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(4, 0, 0)
),
requirements.PluginRequirement(
name="yarascan", plugin=yarascan.YaraScan, version=(2, 0, 0)
requirements.VersionRequirement(
name="yarascan", component=yarascan.YaraScan, version=(2, 0, 0)
),
requirements.VersionRequirement(
name="yarascanner", component=yarascan.YaraScanner, version=(2, 0, 0)
+7 -2
View File
@@ -30,8 +30,13 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.VersionRequirement(
name="timeliner",
component=timeliner.TimeLinerInterface,
version=(1, 0, 0),
),
requirements.ListRequirement(
name="pid",
@@ -31,8 +31,8 @@ class Check_syscall(plugins.PluginInterface):
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 0, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsmod", component=lsmod.Lsmod, version=(2, 0, 0)
),
]
@@ -33,8 +33,8 @@ class Check_sysctl(plugins.PluginInterface):
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 0, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsmod", component=lsmod.Lsmod, version=(2, 0, 0)
),
]
@@ -29,8 +29,8 @@ class Check_trap_table(plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsmod", component=lsmod.Lsmod, version=(2, 0, 0)
),
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 0, 0)
@@ -26,11 +26,13 @@ class Kauth_listeners(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 1, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsmod", component=lsmod.Lsmod, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="kauth_scopes", plugin=kauth_scopes.Kauth_scopes, version=(2, 0, 0)
requirements.VersionRequirement(
name="kauth_scopes",
component=kauth_scopes.Kauth_scopes,
version=(2, 0, 0),
),
]
@@ -31,8 +31,8 @@ class Kauth_scopes(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 1, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsmod", component=lsmod.Lsmod, version=(2, 0, 0)
),
]
+2 -2
View File
@@ -71,8 +71,8 @@ class Kevents(interfaces.plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 2, 0)
@@ -28,8 +28,8 @@ class List_Files(plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="mount", plugin=mount.Mount, version=(2, 0, 0)
requirements.VersionRequirement(
name="mount", component=mount.Mount, version=(2, 0, 0)
),
]
+2 -2
View File
@@ -29,8 +29,8 @@ class Lsof(plugins.PluginInterface):
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 0, 0)
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.ListRequirement(
name="pid",
+2 -2
View File
@@ -23,8 +23,8 @@ class Malfind(interfaces.plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.ListRequirement(
name="pid",
+2 -2
View File
@@ -29,8 +29,8 @@ class Netstat(plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 0, 0)
@@ -28,8 +28,8 @@ class Maps(interfaces.plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.ListRequirement(
name="pid",
+2 -2
View File
@@ -24,8 +24,8 @@ class Psaux(plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.ListRequirement(
name="pid",
+2 -2
View File
@@ -28,8 +28,8 @@ class PsTree(plugins.PluginInterface):
description="Kernel module for the OS",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
]
@@ -32,8 +32,8 @@ class Socket_filters(plugins.PluginInterface):
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 0, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsmod", component=lsmod.Lsmod, version=(2, 0, 0)
),
]
@@ -33,8 +33,8 @@ class Trustedbsd(plugins.PluginInterface):
requirements.VersionRequirement(
name="macutils", component=mac.MacUtilities, version=(1, 3, 0)
),
requirements.PluginRequirement(
name="lsmod", plugin=lsmod.Lsmod, version=(2, 0, 0)
requirements.VersionRequirement(
name="lsmod", component=lsmod.Lsmod, version=(2, 0, 0)
),
]
+5 -1
View File
@@ -25,10 +25,14 @@ class TimeLinerType(enum.IntEnum):
CHANGED = 4
class TimeLinerInterface(metaclass=abc.ABCMeta):
class TimeLinerInterface(
interfaces.configuration.VersionableInterface, metaclass=abc.ABCMeta
):
"""Interface defining methods that timeliner will use to generate a body
file."""
_version = (1, 0, 0)
@abc.abstractmethod
def generate_timeline(
self,
@@ -38,17 +38,17 @@ class Callbacks(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="ssdt", plugin=ssdt.SSDT, version=(2, 0, 0)
requirements.VersionRequirement(
name="ssdt", component=ssdt.SSDT, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="poolscanner", plugin=poolscanner.PoolScanner, version=(3, 0, 0)
requirements.VersionRequirement(
name="poolscanner", component=poolscanner.PoolScanner, version=(3, 0, 0)
),
requirements.PluginRequirement(
name="driverirp", plugin=driverirp.DriverIrp, version=(1, 0, 0)
requirements.VersionRequirement(
name="driverirp", component=driverirp.DriverIrp, version=(1, 0, 0)
),
requirements.PluginRequirement(
name="handles", plugin=handles.Handles, version=(3, 0, 0)
requirements.VersionRequirement(
name="handles", component=handles.Handles, version=(3, 0, 0)
),
]
@@ -27,8 +27,8 @@ class CmdLine(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.ListRequirement(
name="pid",
@@ -38,8 +38,8 @@ class CmdScan(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.PluginRequirement(
name="consoles", plugin=consoles.Consoles, version=(3, 0, 0)
requirements.VersionRequirement(
name="consoles", component=consoles.Consoles, version=(3, 0, 0)
),
requirements.BooleanRequirement(
name="no_registry",
@@ -48,8 +48,11 @@ class Consoles(interfaces.plugins.PluginInterface):
requirements.VersionRequirement(
name="verinfo", component=verinfo.VerInfo, version=(1, 0, 0)
),
requirements.PluginRequirement(
name="hivelist", plugin=hivelist.HiveList, version=(2, 0, 0)
requirements.VersionRequirement(
name="info", component=info.Info, version=(2, 0, 0)
),
requirements.VersionRequirement(
name="hivelist", component=hivelist.HiveList, version=(2, 0, 0)
),
requirements.BooleanRequirement(
name="no_registry",
@@ -31,12 +31,12 @@ class DeskScan(desktops.Desktops):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="desktops", plugin=desktops.Desktops, version=(1, 0, 0)
requirements.VersionRequirement(
name="desktops", component=desktops.Desktops, version=(1, 0, 0)
),
requirements.PluginRequirement(
requirements.VersionRequirement(
name="windowstations",
plugin=windowstations.WindowStations,
component=windowstations.WindowStations,
version=(1, 0, 0),
),
]
@@ -31,9 +31,9 @@ class Desktops(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
requirements.VersionRequirement(
name="windowstations",
plugin=windowstations.WindowStations,
component=windowstations.WindowStations,
version=(1, 0, 0),
),
]
@@ -89,8 +89,8 @@ class DeviceTree(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="driverscan", plugin=driverscan.DriverScan, version=(2, 0, 0)
requirements.VersionRequirement(
name="driverscan", component=driverscan.DriverScan, version=(2, 0, 0)
),
]
@@ -91,14 +91,14 @@ class DirectSystemCalls(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.VersionRequirement(
name="yarascanner", component=yarascan.YaraScanner, version=(2, 1, 0)
),
requirements.PluginRequirement(
name="yarascan", plugin=yarascan.YaraScan, version=(2, 0, 0)
requirements.VersionRequirement(
name="yarascan", component=yarascan.YaraScan, version=(2, 0, 0)
),
]
@@ -36,6 +36,11 @@ class DllList(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterface):
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.VersionRequirement(
name="timeliner",
component=timeliner.TimeLinerInterface,
version=(1, 0, 0),
),
requirements.VersionRequirement(
name="psscan", component=psscan.PsScan, version=(2, 0, 0)
),
@@ -58,14 +58,14 @@ class DriverIrp(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="ssdt", plugin=ssdt.SSDT, version=(2, 0, 0)
requirements.VersionRequirement(
name="ssdt", component=ssdt.SSDT, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="driverscan", plugin=driverscan.DriverScan, version=(2, 0, 0)
requirements.VersionRequirement(
name="driverscan", component=driverscan.DriverScan, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="modules", plugin=modules.Modules, version=(3, 0, 0)
requirements.VersionRequirement(
name="modules", component=modules.Modules, version=(3, 0, 0)
),
]
@@ -25,14 +25,14 @@ class DriverModule(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="ssdt", plugin=ssdt.SSDT, version=(2, 0, 0)
requirements.VersionRequirement(
name="ssdt", component=ssdt.SSDT, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="driverscan", plugin=driverscan.DriverScan, version=(2, 0, 0)
requirements.VersionRequirement(
name="driverscan", component=driverscan.DriverScan, version=(2, 0, 0)
),
requirements.PluginRequirement(
name="modules", plugin=modules.Modules, version=(3, 0, 0)
requirements.VersionRequirement(
name="modules", component=modules.Modules, version=(3, 0, 0)
),
]
@@ -24,8 +24,11 @@ class DriverScan(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="poolscanner", plugin=poolscanner.PoolScanner, version=(3, 0, 0)
requirements.VersionRequirement(
name="poolscanner", component=poolscanner.PoolScanner, version=(3, 0, 0)
),
requirements.VersionRequirement(
name="modules", component=modules.Modules, version=(3, 0, 0)
),
]
@@ -39,11 +39,11 @@ class Envars(interfaces.plugins.PluginInterface):
description="Suppress common and non-persistent variables",
optional=True,
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.PluginRequirement(
name="hivelist", plugin=hivelist.HiveList, version=(2, 0, 0)
requirements.VersionRequirement(
name="hivelist", component=hivelist.HiveList, version=(2, 0, 0)
),
]
@@ -24,8 +24,8 @@ class FileScan(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="poolscanner", plugin=poolscanner.PoolScanner, version=(3, 0, 0)
requirements.VersionRequirement(
name="poolscanner", component=poolscanner.PoolScanner, version=(3, 0, 0)
),
]
@@ -68,8 +68,8 @@ class GetServiceSIDs(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="hivelist", plugin=hivelist.HiveList, version=(2, 0, 0)
requirements.VersionRequirement(
name="hivelist", component=hivelist.HiveList, version=(2, 0, 0)
),
]
@@ -83,11 +83,11 @@ class GetSIDs(interfaces.plugins.PluginInterface):
element_type=int,
optional=True,
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.PluginRequirement(
name="hivelist", plugin=hivelist.HiveList, version=(2, 0, 0)
requirements.VersionRequirement(
name="hivelist", component=hivelist.HiveList, version=(2, 0, 0)
),
]
@@ -35,8 +35,8 @@ class Handles(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.VersionRequirement(
name="psscan", component=psscan.PsScan, version=(2, 0, 0)
@@ -46,12 +46,12 @@ class IndirectSystemCalls(direct_system_calls.DirectSystemCalls):
requirements.VersionRequirement(
name="yarascanner", component=yarascan.YaraScanner, version=(2, 1, 0)
),
requirements.PluginRequirement(
name="yarascan", plugin=yarascan.YaraScan, version=(2, 0, 0)
requirements.VersionRequirement(
name="yarascan", component=yarascan.YaraScan, version=(2, 0, 0)
),
requirements.PluginRequirement(
requirements.VersionRequirement(
name="direct_system_calls",
plugin=direct_system_calls.DirectSystemCalls,
component=direct_system_calls.DirectSystemCalls,
version=(2, 0, 0),
),
]
@@ -27,8 +27,8 @@ class Memmap(interfaces.plugins.PluginInterface):
description="Windows kernel",
architectures=["Intel32", "Intel64"],
),
requirements.PluginRequirement(
name="pslist", plugin=pslist.PsList, version=(3, 0, 0)
requirements.VersionRequirement(
name="pslist", component=pslist.PsList, version=(3, 0, 0)
),
requirements.IntRequirement(
name="pid",

Some files were not shown because too many files have changed in this diff Show More