mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-29 04:54:51 +02:00
Yarascan: Fixes #209 by returning matched strings
This commit is contained in:
@@ -75,10 +75,10 @@ class VadYaraScan(interfaces.plugins.PluginInterface):
|
||||
filter_func = filter_func):
|
||||
layer_name = task.add_process_layer()
|
||||
layer = self.context.layers[layer_name]
|
||||
for offset, name in layer.scan(context = self.context,
|
||||
scanner = yarascan.YaraScanner(rules = rules),
|
||||
sections = self.get_vad_maps(task)):
|
||||
yield (0, (format_hints.Hex(offset), task.UniqueProcessId, name))
|
||||
for offset, name, value in layer.scan(context = self.context,
|
||||
scanner = yarascan.YaraScanner(rules = rules),
|
||||
sections = self.get_vad_maps(task)):
|
||||
yield (0, (format_hints.Hex(offset), task.UniqueProcessId, name, value))
|
||||
|
||||
@staticmethod
|
||||
def get_vad_maps(task: interfaces.objects.ObjectInterface) -> Iterable[Tuple[int, int]]:
|
||||
@@ -98,4 +98,5 @@ class VadYaraScan(interfaces.plugins.PluginInterface):
|
||||
yield (start, end - start)
|
||||
|
||||
def run(self):
|
||||
return renderers.TreeGrid([('Offset', format_hints.Hex), ('Pid', int), ('Rule', str)], self._generator())
|
||||
return renderers.TreeGrid([('Offset', format_hints.Hex), ('Pid', int), ('Rule', str), ('Value', bytes)],
|
||||
self._generator())
|
||||
|
||||
Reference in New Issue
Block a user