Add in initial implementation of ContextFactories as classes. This is probably not the right way to do things, so I'll be trying out making them as objects with a function chain for applying modifications in a little while.

This commit is contained in:
Mike Auty
2015-01-16 11:29:12 +00:00
parent 246974de36
commit f04122f640
5 changed files with 17 additions and 40 deletions
+6 -29
View File
@@ -16,16 +16,12 @@ from volatility.framework.symbols import vtypes, native
def test_symbols():
native_list = native.x86NativeTable
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, native_list)
# ctx = framework.Context(native_list)
# ctx.symbol_space.append(native_list)
ctx = utils_load_as()
print("Symbols,", native_list.structures)
print("Symbols,", ctx.symbol_space.natives.structures)
for i in list(ntkrnlmp.structures):
for i in list(ctx.symbol_space['ntkrnlmp'].structures):
symbol = ctx.symbol_space.get_structure('ntkrnlmp!' + i)
print(symbol.vol.structure_name, symbol, symbol.vol.size)
_ = symbol(ctx, objects.ObjectInformation(layer_name = '', offset = 0))
@@ -34,26 +30,16 @@ def test_symbols():
def utils_load_as():
nativelst = native.x86NativeTable
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst)
ctx = framework.Context(nativelst)
# ctx.symbol_space.append(nativelst)
ctx.symbol_space.append(ntkrnlmp)
return ctx
return framework.contexts.ContextWindowsX86()()
def test_memory():
nativelst = native.x86NativeTable
ctx = utils_load_as()
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
virtual_types['TEST_POINTER'] = [0x4, {'point1': [0x0, ['pointer', ['TEST_SYMBOL']]]}]
virtual_types['TEST_SYMBOL'] = [0x6, {'test1': [0x0, ['unsigned int']], 'test2': [0x4, ['unsigned short']]}]
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst)
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, ctx.symbol_space.natives)
ctx = framework.Context(nativelst)
ctx.symbol_space.append(ntkrnlmp)
base = layers.physical.FileLayer(ctx, 'data', filename = 'trig_data.bin')
@@ -125,16 +111,7 @@ def test_translation():
def test_plugin():
nativelst = native.x86NativeTable
ctx = framework.Context(nativelst)
import volatility.framework.symbols.windows as windows
virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst)
ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD)
ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY)
ctx.symbol_space.append(ntkrnlmp)
ctx = utils_load_as()
base = layers.physical.FileLayer(ctx, 'data', filename = '/home/mike/memory/private/jon-fres.dmp')
ctx.add_layer(base)
+1 -1
View File
@@ -36,7 +36,7 @@ def require_version(*args):
".".join([str(x) for x in args[0:2]]))
from volatility.framework import interfaces, symbols, layers
from volatility.framework import interfaces, symbols, layers, contexts
class Context(interfaces.context.ContextInterface):
+6 -6
View File
@@ -1,5 +1,5 @@
import volatility
from volatility.framework.interfaces import layers
from volatility.framework import layers
from volatility.framework.symbols import vtypes, native, windows
__author__ = 'mike'
@@ -7,7 +7,7 @@ __author__ = 'mike'
from volatility.framework import interfaces
class ContextPhysicalLoader(interfaces.context.ContextFactory):
class ContextPhysicalLoaderInterface(interfaces.context.ContextFactoryInterface):
def construct_physical_layers(self, context):
# TODO: Add in the physical layer automagic to determine the layering
# Ideally allow for the plugin to specify the layering, but if not then guess at the best one
@@ -17,14 +17,14 @@ class ContextPhysicalLoader(interfaces.context.ContextFactory):
### NATIVE TYPES
class Context32Bit(ContextPhysicalLoader):
class Context32Bit(ContextPhysicalLoaderInterface):
def construct_context(self):
"""Creates a base context with the 32-bit NativeTables"""
native_list = native.x86NativeTable
return volatility.framework.Context(native_list)
class Context64Bit(ContextPhysicalLoader):
class Context64Bit(ContextPhysicalLoaderInterface):
def construct_context(self):
"""Creates a base context with the 32-bit NativeTables"""
native_list = native.x64NativeTable
@@ -61,11 +61,11 @@ class ContextWindowsX86(ContextIntel):
def __init__(self):
from volatility.framework import xp_sp2_x86_vtypes
self.virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
self._virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types
def construct_os_symbols(self, context):
virtual_types = self._virtual_types
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types)
ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, context.symbol_space.natives)
ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD)
ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY)
context.symbol_space.append(ntkrnlmp)
+3 -2
View File
@@ -45,10 +45,10 @@ class ContextInterface(object, metaclass = ABCMeta):
"""
class ContextFactory(object, metaclass = ABCMeta):
class ContextFactoryInterface(object, metaclass = ABCMeta):
"""Class to establish and load the appropriate components of the context for a given operating system"""
def establish_context(self):
def __call__(self):
"""Constructs a standard context based on the architecture information
The context is modified
@@ -57,6 +57,7 @@ class ContextFactory(object, metaclass = ABCMeta):
self.construct_physical_layers(context)
self.construct_architecture(context)
self.construct_os_symbols(context)
return context
@abstractmethod
def construct_context(self):
@@ -2,12 +2,11 @@ __author__ = 'mike'
import collections.abc
import volatility.framework.objects as objects
from volatility.framework import objects
class _ETHREAD(objects.Struct):
def owning_process(self, kernel_layer = None):
"""Return the EPROCESS that owns this thread"""
return self.ThreadsProcess.dereference(kernel_layer)