mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-29 04:54:51 +02:00
#118 - black formatted
This commit is contained in:
@@ -6,7 +6,14 @@ import logging
|
||||
|
||||
from typing import Iterator, List, Tuple, Iterable
|
||||
|
||||
from volatility3.framework import exceptions, layers, renderers, interfaces, constants, symbols
|
||||
from volatility3.framework import (
|
||||
exceptions,
|
||||
layers,
|
||||
renderers,
|
||||
interfaces,
|
||||
constants,
|
||||
symbols,
|
||||
)
|
||||
from volatility3.framework.configuration import requirements
|
||||
from volatility3.framework.objects import utility
|
||||
from volatility3.framework.renderers import format_hints
|
||||
@@ -117,9 +124,7 @@ class Timers(interfaces.plugins.PluginInterface):
|
||||
|
||||
if versions.is_windows_7(
|
||||
context=context, symbol_table=symbol_table
|
||||
) or versions.is_windows_8_or_later(
|
||||
context=context, symbol_table=symbol_table
|
||||
):
|
||||
) or versions.is_windows_8_or_later(context=context, symbol_table=symbol_table):
|
||||
# Starting with Windows 7, there is no more KiTimerTableListHead. The list is
|
||||
# at _KPCR.PrcbData.TimerTable.TimerEntries
|
||||
# See http://pastebin.com/FiRsGW3f
|
||||
@@ -143,11 +148,11 @@ class Timers(interfaces.plugins.PluginInterface):
|
||||
|
||||
elif versions.is_xp_or_2003(
|
||||
context=context, symbol_table=symbol_table
|
||||
) or versions.is_vista_or_later(
|
||||
context=context, symbol_table=symbol_table
|
||||
):
|
||||
) or versions.is_vista_or_later(context=context, symbol_table=symbol_table):
|
||||
is_64bit = symbols.symbol_table_is_64bit(context, symbol_table)
|
||||
if is_64bit or versions.is_vista_or_later(context=context, symbol_table=symbol_table):
|
||||
if is_64bit or versions.is_vista_or_later(
|
||||
context=context, symbol_table=symbol_table
|
||||
):
|
||||
# On XP x64, Windows 2003 SP1-SP2, and Vista SP0-SP2, KiTimerTableListHead
|
||||
# is an array of 512 _KTIMER_TABLE_ENTRY structs.
|
||||
array_size = 512
|
||||
@@ -172,7 +177,6 @@ class Timers(interfaces.plugins.PluginInterface):
|
||||
else:
|
||||
raise NotImplementedError("This version of Windows is not supported!")
|
||||
|
||||
|
||||
def _generator(self) -> Iterator[Tuple]:
|
||||
kernel = self.context.modules[self.config["kernel"]]
|
||||
layer_name = kernel.layer_name
|
||||
@@ -248,7 +252,6 @@ class Timers(interfaces.plugins.PluginInterface):
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
def run(self):
|
||||
return renderers.TreeGrid(
|
||||
[
|
||||
|
||||
@@ -453,9 +453,9 @@ class FILE_OBJECT(objects.StructType, pool.ExecutiveObject):
|
||||
].is_valid(self.FileName.Buffer)
|
||||
|
||||
def file_name_with_device(self) -> Union[str, interfaces.renderers.BaseAbsentValue]:
|
||||
name: Union[str, interfaces.renderers.BaseAbsentValue] = (
|
||||
renderers.UnreadableValue()
|
||||
)
|
||||
name: Union[
|
||||
str, interfaces.renderers.BaseAbsentValue
|
||||
] = renderers.UnreadableValue()
|
||||
|
||||
# this pointer needs to be checked against native_layer_name because the object may
|
||||
# be instantiated from a primary (virtual) layer or a memory (physical) layer.
|
||||
@@ -1020,6 +1020,7 @@ class KTIMER(objects.StructType):
|
||||
layer_name=self.vol.layer_name,
|
||||
offset=self.Dpc.vol.offset,
|
||||
)
|
||||
|
||||
def valid_type(self):
|
||||
return self.Header.Type in self.VALID_TYPES
|
||||
|
||||
|
||||
Reference in New Issue
Block a user