diff --git a/volatility3/framework/plugins/mac/bash.py b/volatility3/framework/plugins/mac/bash.py index d1547dcc3..1929e35f7 100644 --- a/volatility3/framework/plugins/mac/bash.py +++ b/volatility3/framework/plugins/mac/bash.py @@ -25,7 +25,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)), requirements.ListRequirement(name = 'pid', @@ -35,7 +35,8 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface): ] def _generator(self, tasks): - is_32bit = not symbols.symbol_table_is_64bit(self.context, self.config["darwin.symbol_table_name"]) + darwin = self.context.modules[self.config['kernel']] + is_32bit = not symbols.symbol_table_is_64bit(self.context, darwin.symbol_table_name) if is_32bit: pack_format = "I" bash_json_file = "bash32" @@ -65,7 +66,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface): for address in proc_layer.scan(self.context, scanners.BytesScanner(b"#"), sections = task.get_process_memory_sections(self.context, - self.config['darwin'], + self.config['kernel'], rw_no_file = True)): bang_addrs.append(struct.pack(pack_format, address)) @@ -74,7 +75,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface): for address, _ in proc_layer.scan(self.context, scanners.MultiStringScanner(bang_addrs), sections = task.get_process_memory_sections(self.context, - self.config['darwin'], + self.config['kernel'], rw_no_file = True)): hist = self.context.object(bash_table_name + constants.BANG + "hist_entry", offset = address - ts_offset, @@ -94,7 +95,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface): ("Command", str)], self._generator( list_tasks(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func))) def generate_timeline(self): @@ -103,7 +104,7 @@ class Bash(plugins.PluginInterface, timeliner.TimeLinerInterface): for row in self._generator( list_tasks(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func)): _depth, row_data = row description = f"{row_data[0]} ({row_data[1]}): \"{row_data[3]}\"" diff --git a/volatility3/framework/plugins/mac/check_syscall.py b/volatility3/framework/plugins/mac/check_syscall.py index 4d96c1733..3a0cd28c9 100644 --- a/volatility3/framework/plugins/mac/check_syscall.py +++ b/volatility3/framework/plugins/mac/check_syscall.py @@ -23,16 +23,16 @@ class Check_syscall(plugins.PluginInterface): @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)) ] def _generator(self): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] - mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin']) + mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel']) handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) @@ -54,7 +54,7 @@ class Check_syscall(plugins.PluginInterface): continue module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, - call_addr, self.config['darwin']) + call_addr, self.config['kernel']) yield (0, (format_hints.Hex(table.vol.offset), "SysCall", i, format_hints.Hex(call_addr), module_name, symbol_name)) diff --git a/volatility3/framework/plugins/mac/check_sysctl.py b/volatility3/framework/plugins/mac/check_sysctl.py index 0468310d6..f7a8973ff 100644 --- a/volatility3/framework/plugins/mac/check_sysctl.py +++ b/volatility3/framework/plugins/mac/check_sysctl.py @@ -25,7 +25,7 @@ class Check_sysctl(plugins.PluginInterface): @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)) @@ -113,9 +113,9 @@ class Check_sysctl(plugins.PluginInterface): break def _generator(self): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] - mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin']) + mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel']) handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) @@ -128,7 +128,7 @@ class Check_sysctl(plugins.PluginInterface): continue module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, check_addr, - self.config['darwin']) + self.config['kernel']) yield (0, (name, sysctl.oid_number, sysctl.get_perms(), format_hints.Hex(check_addr), val, module_name, symbol_name)) diff --git a/volatility3/framework/plugins/mac/check_trap_table.py b/volatility3/framework/plugins/mac/check_trap_table.py index 3703c6f0c..0976d6ea0 100644 --- a/volatility3/framework/plugins/mac/check_trap_table.py +++ b/volatility3/framework/plugins/mac/check_trap_table.py @@ -24,16 +24,16 @@ class Check_trap_table(plugins.PluginInterface): @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)), ] def _generator(self): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] - mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin']) + mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel']) handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) @@ -49,7 +49,7 @@ class Check_trap_table(plugins.PluginInterface): continue module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, call_addr, - self.config['darwin']) + self.config['kernel']) yield (0, (format_hints.Hex(table.vol.offset), "TrapTable", i, format_hints.Hex(call_addr), module_name, symbol_name)) diff --git a/volatility3/framework/plugins/mac/ifconfig.py b/volatility3/framework/plugins/mac/ifconfig.py index 826f5761b..8e72528c5 100644 --- a/volatility3/framework/plugins/mac/ifconfig.py +++ b/volatility3/framework/plugins/mac/ifconfig.py @@ -16,13 +16,13 @@ class Ifconfig(plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)) ] def _generator(self): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] try: list_head = kernel.object_from_symbol(symbol_name = "ifnet_head") diff --git a/volatility3/framework/plugins/mac/kauth_listeners.py b/volatility3/framework/plugins/mac/kauth_listeners.py index 803664350..42eaa4582 100644 --- a/volatility3/framework/plugins/mac/kauth_listeners.py +++ b/volatility3/framework/plugins/mac/kauth_listeners.py @@ -18,7 +18,7 @@ class Kauth_listeners(interfaces.plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)), @@ -31,13 +31,13 @@ class Kauth_listeners(interfaces.plugins.PluginInterface): """ Enumerates the listeners for each kauth scope """ - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] - mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin']) + mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel']) handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) - for scope in kauth_scopes.Kauth_scopes.list_kauth_scopes(self.context, self.config['darwin']): + for scope in kauth_scopes.Kauth_scopes.list_kauth_scopes(self.context, self.config['kernel']): scope_name = utility.pointer_to_string(scope.ks_identifier, 128) @@ -47,7 +47,7 @@ class Kauth_listeners(interfaces.plugins.PluginInterface): continue module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, callback, - self.config['darwin']) + self.config['kernel']) yield (0, (scope_name, format_hints.Hex(listener.kll_idata), format_hints.Hex(callback), module_name, symbol_name)) diff --git a/volatility3/framework/plugins/mac/kauth_scopes.py b/volatility3/framework/plugins/mac/kauth_scopes.py index 7f5a20d8f..f66c5cc0e 100644 --- a/volatility3/framework/plugins/mac/kauth_scopes.py +++ b/volatility3/framework/plugins/mac/kauth_scopes.py @@ -2,7 +2,7 @@ # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # import logging -from typing import Iterable, Callable, Tuple +from typing import Iterable, Callable from volatility3.framework import renderers, interfaces from volatility3.framework.configuration import requirements @@ -23,7 +23,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)) @@ -34,9 +34,7 @@ class Kauth_scopes(interfaces.plugins.PluginInterface): context: interfaces.context.ContextInterface, kernel_module_name: str, filter_func: Callable[[int], bool] = lambda _: False) -> \ - Iterable[Tuple[interfaces.objects.ObjectInterface, - interfaces.objects.ObjectInterface, - interfaces.objects.ObjectInterface]]: + Iterable[interfaces.objects.ObjectInterface]: """ Enumerates the registered kauth scopes and yields each object Uses smear-safe enumeration API @@ -50,20 +48,20 @@ class Kauth_scopes(interfaces.plugins.PluginInterface): yield scope def _generator(self): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] - mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin']) + mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel']) handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) - for scope in self.list_kauth_scopes(self.context, self.config['darwin']): + for scope in self.list_kauth_scopes(self.context, self.config['kernel']): callback = scope.ks_callback if callback == 0: continue module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, callback, - self.config['darwin']) + self.config['kernel']) identifier = utility.pointer_to_string(scope.ks_identifier, 128) diff --git a/volatility3/framework/plugins/mac/kevents.py b/volatility3/framework/plugins/mac/kevents.py index 47087ce38..6fb8e99af 100644 --- a/volatility3/framework/plugins/mac/kevents.py +++ b/volatility3/framework/plugins/mac/kevents.py @@ -48,7 +48,7 @@ class Kevents(interfaces.plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 2, 0)), @@ -148,7 +148,7 @@ class Kevents(interfaces.plugins.PluginInterface): filter_func = pslist.PsList.create_pid_filter(self.config.get('pid', None)) for task_name, pid, kn in self.list_kernel_events(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func): filter_index = kn.kn_kevent.filter * -1 diff --git a/volatility3/framework/plugins/mac/list_files.py b/volatility3/framework/plugins/mac/list_files.py index edc37c2a0..9c6a6bcdd 100644 --- a/volatility3/framework/plugins/mac/list_files.py +++ b/volatility3/framework/plugins/mac/list_files.py @@ -23,7 +23,7 @@ class List_Files(plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'mount', plugin = mount.Mount, version = (2, 0, 0)), ] @@ -165,7 +165,7 @@ class List_Files(plugins.PluginInterface): yield vnode, full_path def _generator(self): - for vnode, full_path in self.list_files(self.context, self.config['darwin']): + for vnode, full_path in self.list_files(self.context, self.config['kernel']): yield (0, (format_hints.Hex(vnode), full_path)) diff --git a/volatility3/framework/plugins/mac/lsmod.py b/volatility3/framework/plugins/mac/lsmod.py index 18c9a37f7..5cb242b19 100644 --- a/volatility3/framework/plugins/mac/lsmod.py +++ b/volatility3/framework/plugins/mac/lsmod.py @@ -22,7 +22,7 @@ class Lsmod(plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), ] @@ -76,7 +76,7 @@ class Lsmod(plugins.PluginInterface): return def _generator(self): - for module in self.list_modules(self.context, self.config['darwin']): + for module in self.list_modules(self.context, self.config['kernel']): mod_name = utility.array_to_string(module.name) mod_size = module.size diff --git a/volatility3/framework/plugins/mac/lsof.py b/volatility3/framework/plugins/mac/lsof.py index a7f2250cd..6d96f102a 100644 --- a/volatility3/framework/plugins/mac/lsof.py +++ b/volatility3/framework/plugins/mac/lsof.py @@ -21,7 +21,7 @@ class Lsof(plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)), @@ -32,11 +32,12 @@ class Lsof(plugins.PluginInterface): ] def _generator(self, tasks): + darwin = self.context.modules[self.config['kernel']] for task in tasks: pid = task.p_pid - for _, filepath, fd in mac.MacUtilities.files_descriptors_for_process(self.context, self.config[ - 'darwin.symbol_table_name'], + for _, filepath, fd in mac.MacUtilities.files_descriptors_for_process(self.context, + darwin.symbol_table_name, task): if filepath and len(filepath) > 0: yield (0, (pid, fd, filepath)) @@ -48,5 +49,5 @@ class Lsof(plugins.PluginInterface): return renderers.TreeGrid([("PID", int), ("File Descriptor", int), ("File Path", str)], self._generator( list_tasks(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func))) diff --git a/volatility3/framework/plugins/mac/malfind.py b/volatility3/framework/plugins/mac/malfind.py index 98d876c90..cf0a80866 100644 --- a/volatility3/framework/plugins/mac/malfind.py +++ b/volatility3/framework/plugins/mac/malfind.py @@ -18,7 +18,7 @@ class Malfind(interfaces.plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)), requirements.ListRequirement(name = 'pid', @@ -38,13 +38,13 @@ class Malfind(interfaces.plugins.PluginInterface): proc_layer = self.context.layers[proc_layer_name] for vma in task.get_map_iter(): - if not vma.is_suspicious(self.context, self.context.modules[self.config['darwin']].symbol_table_name): + if not vma.is_suspicious(self.context, self.context.modules[self.config['kernel']].symbol_table_name): data = proc_layer.read(vma.links.start, 64, pad = True) yield vma, data def _generator(self, tasks): # determine if we're on a 32 or 64 bit kernel - if self.context.modules[self.config['darwin']].get_type("pointer").size == 4: + if self.context.modules[self.config['kernel']].get_type("pointer").size == 4: is_32bit_arch = True else: is_32bit_arch = False @@ -72,5 +72,5 @@ class Malfind(interfaces.plugins.PluginInterface): ("Disasm", interfaces.renderers.Disassembly)], self._generator( list_tasks(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func))) diff --git a/volatility3/framework/plugins/mac/mount.py b/volatility3/framework/plugins/mac/mount.py index 8eceb040c..bc171127e 100644 --- a/volatility3/framework/plugins/mac/mount.py +++ b/volatility3/framework/plugins/mac/mount.py @@ -21,7 +21,7 @@ class Mount(plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)), ] @@ -46,7 +46,7 @@ class Mount(plugins.PluginInterface): yield mount def _generator(self): - for mount in self.list_mounts(self.context, self.config['darwin']): + for mount in self.list_mounts(self.context, self.config['kernel']): vfs = mount.mnt_vfsstat device_name = utility.array_to_string(vfs.f_mntonname) mount_point = utility.array_to_string(vfs.f_mntfromname) diff --git a/volatility3/framework/plugins/mac/netstat.py b/volatility3/framework/plugins/mac/netstat.py index ee5b773f2..4453a8e30 100644 --- a/volatility3/framework/plugins/mac/netstat.py +++ b/volatility3/framework/plugins/mac/netstat.py @@ -24,7 +24,7 @@ class Netstat(plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)), @@ -74,7 +74,7 @@ class Netstat(plugins.PluginInterface): continue if not context.layers[task.vol.native_layer_name].is_valid(socket.vol.offset, - socket.vol.size): + socket.vol.size): continue yield task_name, pid, socket @@ -83,7 +83,7 @@ class Netstat(plugins.PluginInterface): filter_func = pslist.PsList.create_pid_filter(self.config.get('pid', None)) for task_name, pid, socket in self.list_sockets(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func): family = socket.get_family() diff --git a/volatility3/framework/plugins/mac/proc_maps.py b/volatility3/framework/plugins/mac/proc_maps.py index e9912797c..e150c6a55 100644 --- a/volatility3/framework/plugins/mac/proc_maps.py +++ b/volatility3/framework/plugins/mac/proc_maps.py @@ -17,7 +17,7 @@ class Maps(interfaces.plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)), requirements.ListRequirement(name = 'pid', @@ -32,7 +32,7 @@ class Maps(interfaces.plugins.PluginInterface): process_pid = task.p_pid for vma in task.get_map_iter(): - path = vma.get_path(self.context, self.context.modules[self.config['darwin']].symbol_table_name) + path = vma.get_path(self.context, self.context.modules[self.config['kernel']].symbol_table_name) if path == "": path = vma.get_special_path() @@ -47,5 +47,5 @@ class Maps(interfaces.plugins.PluginInterface): ("End", format_hints.Hex), ("Protection", str), ("Map Name", str)], self._generator( list_tasks(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func))) diff --git a/volatility3/framework/plugins/mac/psaux.py b/volatility3/framework/plugins/mac/psaux.py index 73d4b16c5..5206e5b2b 100644 --- a/volatility3/framework/plugins/mac/psaux.py +++ b/volatility3/framework/plugins/mac/psaux.py @@ -19,7 +19,7 @@ class Psaux(plugins.PluginInterface): @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)), requirements.ListRequirement(name = 'pid', @@ -96,5 +96,5 @@ class Psaux(plugins.PluginInterface): return renderers.TreeGrid([("PID", int), ("Process", str), ("Argc", int), ("Arguments", str)], self._generator( list_tasks(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = filter_func))) diff --git a/volatility3/framework/plugins/mac/pslist.py b/volatility3/framework/plugins/mac/pslist.py index b87822efe..c094adba8 100644 --- a/volatility3/framework/plugins/mac/pslist.py +++ b/volatility3/framework/plugins/mac/pslist.py @@ -23,7 +23,7 @@ class PsList(interfaces.plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 1, 0)), requirements.ChoiceRequirement(name = 'pslist_method', @@ -89,7 +89,7 @@ class PsList(interfaces.plugins.PluginInterface): list_tasks = self.get_list_tasks(self.config.get('pslist_method', self.pslist_methods[0])) for task in list_tasks(self.context, - self.config['darwin'], + self.config['kernel'], filter_func = self.create_pid_filter(self.config.get('pid', None))): pid = task.p_pid ppid = task.p_ppid diff --git a/volatility3/framework/plugins/mac/pstree.py b/volatility3/framework/plugins/mac/pstree.py index a9846d0db..76219c457 100644 --- a/volatility3/framework/plugins/mac/pstree.py +++ b/volatility3/framework/plugins/mac/pstree.py @@ -24,7 +24,7 @@ class PsTree(plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.PluginRequirement(name = 'pslist', plugin = pslist.PsList, version = (3, 0, 0)) ] @@ -48,7 +48,7 @@ class PsTree(plugins.PluginInterface): """Generates the tree list of processes""" list_tasks = pslist.PsList.get_list_tasks(self.config.get('pslist_method', pslist.PsList.pslist_methods[0])) - for proc in list_tasks(self.context, self.config['darwin']): + for proc in list_tasks(self.context, self.config['kernel']): self._processes[proc.p_pid] = proc # Build the child/level maps diff --git a/volatility3/framework/plugins/mac/socket_filters.py b/volatility3/framework/plugins/mac/socket_filters.py index be21bc7d1..ee1b83ed7 100644 --- a/volatility3/framework/plugins/mac/socket_filters.py +++ b/volatility3/framework/plugins/mac/socket_filters.py @@ -24,16 +24,16 @@ class Socket_filters(plugins.PluginInterface): @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 0, 0)), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)) ] def _generator(self): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] - mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin']) + mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel']) handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) diff --git a/volatility3/framework/plugins/mac/timers.py b/volatility3/framework/plugins/mac/timers.py index 5ce973d5c..42b71134a 100644 --- a/volatility3/framework/plugins/mac/timers.py +++ b/volatility3/framework/plugins/mac/timers.py @@ -23,16 +23,16 @@ class Timers(plugins.PluginInterface): @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 3, 0)), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)) ] def _generator(self): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] - mods = lsmod.Lsmod.list_modules(self.context, self.config['darwin']) + mods = lsmod.Lsmod.list_modules(self.context, self.config['kernel']) handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) @@ -69,7 +69,7 @@ class Timers(plugins.PluginInterface): entry_time = -1 module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, handler, - self.config['darwin']) + self.config['kernel']) yield (0, (format_hints.Hex(handler), format_hints.Hex(timer.param0), format_hints.Hex(timer.param1), timer.deadline, entry_time, module_name, symbol_name)) diff --git a/volatility3/framework/plugins/mac/trustedbsd.py b/volatility3/framework/plugins/mac/trustedbsd.py index 615e5ea64..5d0eba669 100644 --- a/volatility3/framework/plugins/mac/trustedbsd.py +++ b/volatility3/framework/plugins/mac/trustedbsd.py @@ -25,14 +25,14 @@ class Trustedbsd(plugins.PluginInterface): @classmethod def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), requirements.VersionRequirement(name = 'macutils', component = mac.MacUtilities, version = (1, 3, 0)), requirements.PluginRequirement(name = 'lsmod', plugin = lsmod.Lsmod, version = (2, 0, 0)) ] def _generator(self, mods: Iterator[Any]): - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] handlers = mac.MacUtilities.generate_kernel_handler_info(self.context, kernel.layer_name, kernel, mods) @@ -65,7 +65,7 @@ class Trustedbsd(plugins.PluginInterface): continue module_name, symbol_name = mac.MacUtilities.lookup_module_address(self.context, handlers, call_addr, - self.config['darwin']) + self.config['kernel']) yield (0, (check, ent_name, format_hints.Hex(call_addr), module_name, symbol_name)) @@ -73,4 +73,4 @@ class Trustedbsd(plugins.PluginInterface): return renderers.TreeGrid([("Member", str), ("Policy Name", str), ("Handler Address", format_hints.Hex), ("Handler Module", str), ("Handler Symbol", str)], self._generator( - lsmod.Lsmod.list_modules(self.context, self.config['darwin']))) + lsmod.Lsmod.list_modules(self.context, self.config['kernel']))) diff --git a/volatility3/framework/plugins/mac/vfsevents.py b/volatility3/framework/plugins/mac/vfsevents.py index 71915bcad..9259956e9 100644 --- a/volatility3/framework/plugins/mac/vfsevents.py +++ b/volatility3/framework/plugins/mac/vfsevents.py @@ -20,7 +20,7 @@ class VFSevents(interfaces.plugins.PluginInterface): @classmethod def get_requirements(cls): return [ - requirements.ModuleRequirement(name = 'darwin', description = 'Kernel module for the OS', + requirements.ModuleRequirement(name = 'kernel', description = 'Kernel module for the OS', architectures = ["Intel32", "Intel64"]), ] @@ -30,7 +30,7 @@ class VFSevents(interfaces.plugins.PluginInterface): Also lists which event(s) a process is registered for """ - kernel = self.context.modules[self.config['darwin']] + kernel = self.context.modules[self.config['kernel']] watcher_table = kernel.object_from_symbol("watcher_table")