diff --git a/volatility/framework/symbols/windows/__init__.py b/volatility/framework/symbols/windows/__init__.py index 74f1d2d3b..0261268e1 100644 --- a/volatility/framework/symbols/windows/__init__.py +++ b/volatility/framework/symbols/windows/__init__.py @@ -14,6 +14,7 @@ class WindowsKernelIntermedSymbols(intermed.IntermediateSymbolTable): self.set_type_class('_LIST_ENTRY', extensions._LIST_ENTRY) self.set_type_class('_EPROCESS', extensions._EPROCESS) self.set_type_class('_UNICODE_STRING', extensions._UNICODE_STRING) + self.set_type_class('_CMHIVE', extensions._CMHIVE) @classmethod def get_requirements(cls): diff --git a/volatility/framework/symbols/windows/extensions/__init__.py b/volatility/framework/symbols/windows/extensions/__init__.py index 19253c474..ce0f33791 100644 --- a/volatility/framework/symbols/windows/extensions/__init__.py +++ b/volatility/framework/symbols/windows/extensions/__init__.py @@ -4,7 +4,7 @@ import string from volatility.framework import interfaces from volatility.framework import objects - +from volatility.framework import exceptions # Keep these in a basic module, to prevent import cycles when symbol providers require them @@ -13,6 +13,20 @@ class _ETHREAD(objects.Struct): """Return the EPROCESS that owns this thread""" return self.ThreadsProcess.dereference(kernel_layer) +class _CMHIVE(objects.Struct): + @property + def name(self): + """Determine a name for the hive. Note that some attributes are + unpredictably blank across different OS versions while others are populated, + so we check all possibilities and take the first one that's not empty""" + + for attr in ["FileFullPath", "FileUserName", "HiveRootPath"]: + try: + return getattr(self, attr).String + except (AttributeError, exceptions.InvalidAddressException): + pass + + return None class _UNICODE_STRING(objects.Struct): @property diff --git a/volatility/plugins/windows/hivelist.py b/volatility/plugins/windows/hivelist.py index 2eacf2e9d..9cd1a0c04 100644 --- a/volatility/plugins/windows/hivelist.py +++ b/volatility/plugins/windows/hivelist.py @@ -21,13 +21,8 @@ class HiveList(plugins.PluginInterface): def _generator(self): for hive in self.list_hives(): - try: - FileFullPath = hive.FileFullPath.String - except exceptions.InvalidAddressException: - FileFullPath = "" - yield (0, (format_hints.Hex(hive.vol.offset), - FileFullPath)) + hive.name or "")) def list_hives(self): """Lists all the hives in the primary layer"""