diff --git a/test_rig.py b/test_rig.py index 9b1adb817..b6f177726 100644 --- a/test_rig.py +++ b/test_rig.py @@ -16,16 +16,12 @@ from volatility.framework.symbols import vtypes, native def test_symbols(): native_list = native.x86NativeTable - virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types - - ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, native_list) - # ctx = framework.Context(native_list) # ctx.symbol_space.append(native_list) ctx = utils_load_as() - print("Symbols,", native_list.structures) + print("Symbols,", ctx.symbol_space.natives.structures) - for i in list(ntkrnlmp.structures): + for i in list(ctx.symbol_space['ntkrnlmp'].structures): symbol = ctx.symbol_space.get_structure('ntkrnlmp!' + i) print(symbol.vol.structure_name, symbol, symbol.vol.size) _ = symbol(ctx, objects.ObjectInformation(layer_name = '', offset = 0)) @@ -34,26 +30,16 @@ def test_symbols(): def utils_load_as(): - nativelst = native.x86NativeTable - - virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types - - ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst) - - ctx = framework.Context(nativelst) - # ctx.symbol_space.append(nativelst) - ctx.symbol_space.append(ntkrnlmp) - return ctx + return framework.contexts.ContextWindowsX86()() def test_memory(): - nativelst = native.x86NativeTable + ctx = utils_load_as() virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types virtual_types['TEST_POINTER'] = [0x4, {'point1': [0x0, ['pointer', ['TEST_SYMBOL']]]}] virtual_types['TEST_SYMBOL'] = [0x6, {'test1': [0x0, ['unsigned int']], 'test2': [0x4, ['unsigned short']]}] - ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst) + ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, ctx.symbol_space.natives) - ctx = framework.Context(nativelst) ctx.symbol_space.append(ntkrnlmp) base = layers.physical.FileLayer(ctx, 'data', filename = 'trig_data.bin') @@ -125,16 +111,7 @@ def test_translation(): def test_plugin(): - nativelst = native.x86NativeTable - ctx = framework.Context(nativelst) - - import volatility.framework.symbols.windows as windows - - virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types - ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, nativelst) - ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD) - ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY) - ctx.symbol_space.append(ntkrnlmp) + ctx = utils_load_as() base = layers.physical.FileLayer(ctx, 'data', filename = '/home/mike/memory/private/jon-fres.dmp') ctx.add_layer(base) diff --git a/volatility/framework/__init__.py b/volatility/framework/__init__.py index 648d4727d..f6749a1ee 100644 --- a/volatility/framework/__init__.py +++ b/volatility/framework/__init__.py @@ -36,7 +36,7 @@ def require_version(*args): ".".join([str(x) for x in args[0:2]])) -from volatility.framework import interfaces, symbols, layers +from volatility.framework import interfaces, symbols, layers, contexts class Context(interfaces.context.ContextInterface): diff --git a/volatility/framework/contexts/__init__.py b/volatility/framework/contexts/__init__.py index b5f36534d..7dc249327 100644 --- a/volatility/framework/contexts/__init__.py +++ b/volatility/framework/contexts/__init__.py @@ -1,5 +1,5 @@ import volatility -from volatility.framework.interfaces import layers +from volatility.framework import layers from volatility.framework.symbols import vtypes, native, windows __author__ = 'mike' @@ -7,7 +7,7 @@ __author__ = 'mike' from volatility.framework import interfaces -class ContextPhysicalLoader(interfaces.context.ContextFactory): +class ContextPhysicalLoaderInterface(interfaces.context.ContextFactoryInterface): def construct_physical_layers(self, context): # TODO: Add in the physical layer automagic to determine the layering # Ideally allow for the plugin to specify the layering, but if not then guess at the best one @@ -17,14 +17,14 @@ class ContextPhysicalLoader(interfaces.context.ContextFactory): ### NATIVE TYPES -class Context32Bit(ContextPhysicalLoader): +class Context32Bit(ContextPhysicalLoaderInterface): def construct_context(self): """Creates a base context with the 32-bit NativeTables""" native_list = native.x86NativeTable return volatility.framework.Context(native_list) -class Context64Bit(ContextPhysicalLoader): +class Context64Bit(ContextPhysicalLoaderInterface): def construct_context(self): """Creates a base context with the 32-bit NativeTables""" native_list = native.x64NativeTable @@ -61,11 +61,11 @@ class ContextWindowsX86(ContextIntel): def __init__(self): from volatility.framework import xp_sp2_x86_vtypes - self.virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types + self._virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types def construct_os_symbols(self, context): virtual_types = self._virtual_types - ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types) + ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, context.symbol_space.natives) ntkrnlmp.set_structure_class('_ETHREAD', windows._ETHREAD) ntkrnlmp.set_structure_class('_LIST_ENTRY', windows._LIST_ENTRY) context.symbol_space.append(ntkrnlmp) diff --git a/volatility/framework/interfaces/context.py b/volatility/framework/interfaces/context.py index 677c35fa4..67af42ff9 100644 --- a/volatility/framework/interfaces/context.py +++ b/volatility/framework/interfaces/context.py @@ -45,10 +45,10 @@ class ContextInterface(object, metaclass = ABCMeta): """ -class ContextFactory(object, metaclass = ABCMeta): +class ContextFactoryInterface(object, metaclass = ABCMeta): """Class to establish and load the appropriate components of the context for a given operating system""" - def establish_context(self): + def __call__(self): """Constructs a standard context based on the architecture information The context is modified @@ -57,6 +57,7 @@ class ContextFactory(object, metaclass = ABCMeta): self.construct_physical_layers(context) self.construct_architecture(context) self.construct_os_symbols(context) + return context @abstractmethod def construct_context(self): diff --git a/volatility/framework/symbols/windows/__init__.py b/volatility/framework/symbols/windows/__init__.py index 25cc39daa..31fb49423 100644 --- a/volatility/framework/symbols/windows/__init__.py +++ b/volatility/framework/symbols/windows/__init__.py @@ -2,12 +2,11 @@ __author__ = 'mike' import collections.abc -import volatility.framework.objects as objects +from volatility.framework import objects class _ETHREAD(objects.Struct): def owning_process(self, kernel_layer = None): - """Return the EPROCESS that owns this thread""" return self.ThreadsProcess.dereference(kernel_layer)