mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 13:34:53 +02:00
Add in initial implementation of ContextFactories as classes. This is probably not the right way to do things, so I'll be trying out making them as objects with a function chain for applying modifications in a little while.
This commit is contained in:
+6
-29
@@ -16,16 +16,12 @@ from volatility.framework.symbols import vtypes, native
|
||||
def test_symbols():
|
||||
native_list = native.x86NativeTable
|
||||
|
||||
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
|
||||
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, native_list)
|
||||
|
||||
# ctx = framework.Context(native_list)
|
||||
# ctx.symbol_space.append(native_list)
|
||||
ctx = utils_load_as()
|
||||
print("Symbols,", native_list.structures)
|
||||
print("Symbols,", ctx.symbol_space.natives.structures)
|
||||
|
||||
for i in list(ntkrnlmp.structures):
|
||||
for i in list(ctx.symbol_space['ntkrnlmp'].structures):
|
||||
symbol = ctx.symbol_space.get_structure('ntkrnlmp!' + i)
|
||||
print(symbol.vol.structure_name, symbol, symbol.vol.size)
|
||||
_ = symbol(ctx, objects.ObjectInformation(layer_name = '', offset = 0))
|
||||
@@ -34,26 +30,16 @@ def test_symbols():
|
||||
|
||||
|
||||
def utils_load_as():
|
||||
nativelst = native.x86NativeTable
|
||||
|
||||
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
|
||||
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst)
|
||||
|
||||
ctx = framework.Context(nativelst)
|
||||
# ctx.symbol_space.append(nativelst)
|
||||
ctx.symbol_space.append(ntkrnlmp)
|
||||
return ctx
|
||||
return framework.contexts.ContextWindowsX86()()
|
||||
|
||||
|
||||
def test_memory():
|
||||
nativelst = native.x86NativeTable
|
||||
ctx = utils_load_as()
|
||||
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
|
||||
virtual_types['TEST_POINTER'] = [0x4, {'point1': [0x0, ['pointer', ['TEST_SYMBOL']]]}]
|
||||
virtual_types['TEST_SYMBOL'] = [0x6, {'test1': [0x0, ['unsigned int']], 'test2': [0x4, ['unsigned short']]}]
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst)
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, ctx.symbol_space.natives)
|
||||
|
||||
ctx = framework.Context(nativelst)
|
||||
ctx.symbol_space.append(ntkrnlmp)
|
||||
|
||||
base = layers.physical.FileLayer(ctx, 'data', filename = 'trig_data.bin')
|
||||
@@ -125,16 +111,7 @@ def test_translation():
|
||||
|
||||
|
||||
def test_plugin():
|
||||
nativelst = native.x86NativeTable
|
||||
ctx = framework.Context(nativelst)
|
||||
|
||||
import volatility.framework.symbols.windows as windows
|
||||
|
||||
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst)
|
||||
ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD)
|
||||
ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY)
|
||||
ctx.symbol_space.append(ntkrnlmp)
|
||||
ctx = utils_load_as()
|
||||
|
||||
base = layers.physical.FileLayer(ctx, 'data', filename = '/home/mike/memory/private/jon-fres.dmp')
|
||||
ctx.add_layer(base)
|
||||
|
||||
@@ -36,7 +36,7 @@ def require_version(*args):
|
||||
".".join([str(x) for x in args[0:2]]))
|
||||
|
||||
|
||||
from volatility.framework import interfaces, symbols, layers
|
||||
from volatility.framework import interfaces, symbols, layers, contexts
|
||||
|
||||
|
||||
class Context(interfaces.context.ContextInterface):
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
import volatility
|
||||
from volatility.framework.interfaces import layers
|
||||
from volatility.framework import layers
|
||||
from volatility.framework.symbols import vtypes, native, windows
|
||||
|
||||
__author__ = 'mike'
|
||||
@@ -7,7 +7,7 @@ __author__ = 'mike'
|
||||
from volatility.framework import interfaces
|
||||
|
||||
|
||||
class ContextPhysicalLoader(interfaces.context.ContextFactory):
|
||||
class ContextPhysicalLoaderInterface(interfaces.context.ContextFactoryInterface):
|
||||
def construct_physical_layers(self, context):
|
||||
# TODO: Add in the physical layer automagic to determine the layering
|
||||
# Ideally allow for the plugin to specify the layering, but if not then guess at the best one
|
||||
@@ -17,14 +17,14 @@ class ContextPhysicalLoader(interfaces.context.ContextFactory):
|
||||
|
||||
### NATIVE TYPES
|
||||
|
||||
class Context32Bit(ContextPhysicalLoader):
|
||||
class Context32Bit(ContextPhysicalLoaderInterface):
|
||||
def construct_context(self):
|
||||
"""Creates a base context with the 32-bit NativeTables"""
|
||||
native_list = native.x86NativeTable
|
||||
return volatility.framework.Context(native_list)
|
||||
|
||||
|
||||
class Context64Bit(ContextPhysicalLoader):
|
||||
class Context64Bit(ContextPhysicalLoaderInterface):
|
||||
def construct_context(self):
|
||||
"""Creates a base context with the 32-bit NativeTables"""
|
||||
native_list = native.x64NativeTable
|
||||
@@ -61,11 +61,11 @@ class ContextWindowsX86(ContextIntel):
|
||||
def __init__(self):
|
||||
from volatility.framework import xp_sp2_x86_vtypes
|
||||
|
||||
self.virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
|
||||
self._virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
|
||||
|
||||
def construct_os_symbols(self, context):
|
||||
virtual_types = self._virtual_types
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types)
|
||||
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, context.symbol_space.natives)
|
||||
ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD)
|
||||
ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY)
|
||||
context.symbol_space.append(ntkrnlmp)
|
||||
|
||||
@@ -45,10 +45,10 @@ class ContextInterface(object, metaclass = ABCMeta):
|
||||
"""
|
||||
|
||||
|
||||
class ContextFactory(object, metaclass = ABCMeta):
|
||||
class ContextFactoryInterface(object, metaclass = ABCMeta):
|
||||
"""Class to establish and load the appropriate components of the context for a given operating system"""
|
||||
|
||||
def establish_context(self):
|
||||
def __call__(self):
|
||||
"""Constructs a standard context based on the architecture information
|
||||
|
||||
The context is modified
|
||||
@@ -57,6 +57,7 @@ class ContextFactory(object, metaclass = ABCMeta):
|
||||
self.construct_physical_layers(context)
|
||||
self.construct_architecture(context)
|
||||
self.construct_os_symbols(context)
|
||||
return context
|
||||
|
||||
@abstractmethod
|
||||
def construct_context(self):
|
||||
|
||||
@@ -2,12 +2,11 @@ __author__ = 'mike'
|
||||
|
||||
import collections.abc
|
||||
|
||||
import volatility.framework.objects as objects
|
||||
from volatility.framework import objects
|
||||
|
||||
|
||||
class _ETHREAD(objects.Struct):
|
||||
def owning_process(self, kernel_layer = None):
|
||||
|
||||
"""Return the EPROCESS that owns this thread"""
|
||||
return self.ThreadsProcess.dereference(kernel_layer)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user