diff --git a/volatility/framework/plugins/windows/cmdline.py b/volatility/framework/plugins/windows/cmdline.py index a883f4379..932140680 100644 --- a/volatility/framework/plugins/windows/cmdline.py +++ b/volatility/framework/plugins/windows/cmdline.py @@ -1,7 +1,7 @@ # This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # - +import logging from typing import List from volatility.framework import constants, exceptions, renderers, interfaces @@ -9,6 +9,8 @@ from volatility.framework.configuration import requirements from volatility.framework.objects import utility from volatility.plugins.windows import pslist +vollog = logging.getLogger(__name__) + class CmdLine(interfaces.plugins.PluginInterface): """Lists process command line arguments.""" @@ -31,9 +33,13 @@ class CmdLine(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue try: diff --git a/volatility/framework/plugins/windows/dlldump.py b/volatility/framework/plugins/windows/dlldump.py index 38484556c..71c5277e3 100644 --- a/volatility/framework/plugins/windows/dlldump.py +++ b/volatility/framework/plugins/windows/dlldump.py @@ -6,7 +6,7 @@ import logging import ntpath from typing import List -from volatility.framework import interfaces, constants +from volatility.framework import interfaces, constants, exceptions from volatility.framework import renderers from volatility.framework.configuration import requirements from volatility.framework.objects import utility @@ -53,10 +53,14 @@ class DllDump(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) - + + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue for vad in vadinfo.VadInfo.list_vads(proc, filter_func = filter_func): diff --git a/volatility/framework/plugins/windows/malfind.py b/volatility/framework/plugins/windows/malfind.py index d6e2d1eb0..f4e196242 100644 --- a/volatility/framework/plugins/windows/malfind.py +++ b/volatility/framework/plugins/windows/malfind.py @@ -1,15 +1,18 @@ # This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # +import logging from typing import Iterable, Tuple -from volatility.framework import interfaces, symbols +from volatility.framework import interfaces, symbols, exceptions from volatility.framework import renderers from volatility.framework.configuration import requirements from volatility.framework.objects import utility from volatility.framework.renderers import format_hints from volatility.plugins.windows import pslist, vadinfo +vollog = logging.getLogger(__name__) + class Malfind(interfaces.plugins.PluginInterface): """Lists process memory ranges that potentially contain injected code.""" @@ -73,9 +76,13 @@ class Malfind(interfaces.plugins.PluginInterface): Returns: An iterable of VAD instances and the first 64 bytes of data containing in that region """ + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) return proc_layer = context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/moddump.py b/volatility/framework/plugins/windows/moddump.py index 32564ceb4..4a5ecc6f6 100644 --- a/volatility/framework/plugins/windows/moddump.py +++ b/volatility/framework/plugins/windows/moddump.py @@ -5,14 +5,13 @@ import logging from typing import List, Generator, Iterable -from volatility.plugins.windows import pslist, modules - from volatility.framework import constants, exceptions, renderers from volatility.framework import interfaces from volatility.framework.configuration import requirements from volatility.framework.renderers import format_hints from volatility.framework.symbols import intermed from volatility.framework.symbols.windows.extensions import pe +from volatility.plugins.windows import pslist, modules vollog = logging.getLogger(__name__) @@ -60,12 +59,11 @@ class ModDump(interfaces.plugins.PluginInterface): layer_name = layer_name, symbol_table = symbol_table, filter_func = filter_func): + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: - continue - try: # create the session space object in the process' own layer. # not all processes have a valid session pointer. session_space = context.object(symbol_table + constants.BANG + "_MM_SESSION_SPACE", @@ -76,8 +74,10 @@ class ModDump(interfaces.plugins.PluginInterface): continue except exceptions.InvalidAddressException: - vollog.log(constants.LOGLEVEL_VVV, - "Process {} does not have a valid Session".format(proc.UniqueProcessId)) + vollog.log( + constants.LOGLEVEL_VVV, + "Process {} does not have a valid Session or a layer could not be constructed for it".format( + proc_id)) continue # save the layer if we haven't seen the session yet diff --git a/volatility/framework/plugins/windows/procdump.py b/volatility/framework/plugins/windows/procdump.py index 0ac09b1ab..dc2471143 100644 --- a/volatility/framework/plugins/windows/procdump.py +++ b/volatility/framework/plugins/windows/procdump.py @@ -42,13 +42,12 @@ class ProcDump(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) - - try: - proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: - continue + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId + proc_layer_name = proc.add_process_layer() + peb = self._context.object(self.config["nt_symbols"] + constants.BANG + "_PEB", layer_name = proc_layer_name, offset = proc.Peb) @@ -71,14 +70,16 @@ class ProcDump(interfaces.plugins.PluginInterface): result_text = "PE parsing error" except exceptions.SwappedInvalidAddressException as exp: - result_text = "Required memory at {0:#x} is inaccessible (swapped)".format(exp.invalid_address) + result_text = "Process {}: Required memory at {:#x} is inaccessible (swapped)".format( + proc_id, exp.invalid_address) except exceptions.PagedInvalidAddressException as exp: - result_text = "Required memory at {0:#x} is not valid (process exited?)".format(exp.invalid_address) + result_text = "Process {}: Required memory at {:#x} is not valid (process exited?)".format( + proc_id, exp.invalid_address) except exceptions.InvalidAddressException as exp: - result_text = "Required memory at {0:#x} is not valid (incomplete layer {1}?)".format( - exp.invalid_address, exp.layer_name) + result_text = "Process {}: Required memory at {:#x} is not valid (incomplete layer {}?)".format( + proc_id, exp.invalid_address, exp.layer_name) yield (0, (proc.UniqueProcessId, process_name, result_text)) diff --git a/volatility/framework/plugins/windows/strings.py b/volatility/framework/plugins/windows/strings.py index 696b0489f..e961e45c5 100644 --- a/volatility/framework/plugins/windows/strings.py +++ b/volatility/framework/plugins/windows/strings.py @@ -6,7 +6,7 @@ import logging import re from typing import Dict, Generator, List, Set, Tuple -from volatility.framework import interfaces, renderers +from volatility.framework import interfaces, renderers, exceptions from volatility.framework.configuration import requirements from volatility.framework.layers import intel, resources, linear from volatility.framework.renderers import format_hints @@ -95,9 +95,13 @@ class Strings(interfaces.plugins.PluginInterface): for process in pslist.PsList.list_processes(self.context, self.config['primary'], self.config['nt_symbols']): + proc_id = "Unknown" try: + proc_id = process.UniqueProcessId proc_layer_name = process.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format( + proc_id, excp.invalid_address, excp.layer_name)) continue proc_layer = self.context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/svcscan.py b/volatility/framework/plugins/windows/svcscan.py index 554c5b0a2..d020dd2f1 100644 --- a/volatility/framework/plugins/windows/svcscan.py +++ b/volatility/framework/plugins/windows/svcscan.py @@ -5,7 +5,7 @@ import logging from typing import List -from volatility.framework import interfaces, renderers, constants, symbols +from volatility.framework import interfaces, renderers, constants, symbols, exceptions from volatility.framework.configuration import requirements from volatility.framework.layers import scanners from volatility.framework.renderers import format_hints @@ -131,9 +131,13 @@ class SvcScan(interfaces.plugins.PluginInterface): symbol_table = self.config['nt_symbols'], filter_func = filter_func): + proc_id = "Unknown" try: + proc_id = task.UniqueProcessId proc_layer_name = task.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue layer = self.context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/vaddump.py b/volatility/framework/plugins/windows/vaddump.py index 922c9abda..2ba44d055 100644 --- a/volatility/framework/plugins/windows/vaddump.py +++ b/volatility/framework/plugins/windows/vaddump.py @@ -47,9 +47,13 @@ class VadDump(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue proc_layer = self.context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/verinfo.py b/volatility/framework/plugins/windows/verinfo.py index 52b391003..a6e4f186e 100644 --- a/volatility/framework/plugins/windows/verinfo.py +++ b/volatility/framework/plugins/windows/verinfo.py @@ -123,10 +123,14 @@ class VerInfo(interfaces.plugins.PluginInterface): # now go through the process and dll lists for proc in procs: + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: - continue + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) + continue for entry in proc.load_order_modules(): @@ -135,8 +139,6 @@ class VerInfo(interfaces.plugins.PluginInterface): except exceptions.InvalidAddressException: BaseDllName = renderers.UnreadableValue() - session_layer_name = moddump.ModDump.find_session_layer(self.context, session_layers, mod.DllBase) - (major, minor, product, build) = [renderers.NotAvailableValue()] * 4 try: (major, minor, product, build) = self.get_version_information(self._context, pe_table_name, proc_layer_name, entry.DllBase)