Commit Graph
6047 Commits
Author SHA1 Message Date
Andrew Case 36b66f00fe Add delete on close detection to process ghosting. Update plugin to current coding flow 2025-03-24 05:05:08 +00:00
Andrew Case e3d35aa425 update from feedback 2025-03-24 02:49:31 +00:00
Andrew Case 57c07631b0 Add win32 start address listing. Add paths for both thread starting address types 2025-03-23 21:23:42 -05:00
Mike Auty f0153817c5 Add in slots to object model 2025-03-24 00:58:28 +00:00
Odysseas Stavrou bb39081e33 Volshell: Add byteorder argument for display_* functions 2025-03-23 22:29:16 +02:00
Mike Auty e86981c880 Various: Update yarascan plugins to output LayerData instead of just bytes 2025-03-23 00:42:13 +00:00
Mike Auty 6f599fa645 Various: Minor bump malfind functions for all OSes 2025-03-23 00:42:13 +00:00
Mike Auty af01fcdcff Core: Remove unnecessary f-string 2025-03-23 00:42:13 +00:00
Mike Auty c18c6cbf30 Core: Shift renderers from interfaces 2025-03-23 00:42:13 +00:00
Mike Auty 6af8cd09f0 Renderers: Add in fallback method for formatting cellrenderers 2025-03-23 00:42:13 +00:00
Mike Auty 94d6f4f131 CLI: Indicate missing bytes from padded bytes 2025-03-23 00:42:13 +00:00
Mike Auty 85870a9a94 Windows: Update the required framework version for plugins outputting LayerData 2025-03-23 00:42:13 +00:00
Mike Auty 4145ef2c0d Renderers: Add no_surrounding to LayerData and include MINOR version bump 2025-03-23 00:42:11 +00:00
Mike Auty e936b33784 CLI: Fix ruff check error 2025-03-23 00:41:43 +00:00
Mike Auty 2e8d18e7cb Windows: Convert mbrscan over to LayerData output 2025-03-23 00:41:43 +00:00
Mike Auty 2304ea4cbe Windows: Convert mftscan plugins to LayerData output 2025-03-23 00:41:43 +00:00
Mike Auty 1d5d981be1 Windows: Convert malfind to LayerData renderer 2025-03-23 00:41:43 +00:00
Mike Auty ba82067dac CLI: Add in initial LayerData renderer 2025-03-23 00:41:43 +00:00
Mike Auty d3a5883130 Core: Fix up more bad typing operators 2025-03-23 00:41:43 +00:00
Mike Auty 45ee399623 Core: Fix up yet another typo 2025-03-23 00:41:43 +00:00
Mike Auty 16d1b2697c Core: Fix typing for python < 3.10 2025-03-23 00:41:43 +00:00
Mike Auty 4fd501d38f Core: Resolve ruff errors 2025-03-23 00:41:43 +00:00
Mike Auty 1ecd75f665 Core: Apply black to interfaces and the CLI 2025-03-23 00:41:43 +00:00
Mike Auty 453f52ba3e CLI: Add in concept of CellRenderer 2025-03-23 00:41:43 +00:00
Mike Auty 55151f546d Initial work on adding a LayerData renderer type 2025-03-23 00:41:43 +00:00
Andrew Case 6763031df8 Add performance event plugin to detect eBPF malware 2025-03-21 20:28:23 +00:00
ikelosandGitHub 0ddec14cf9 Merge pull request #1724 from volatilityfoundation/dgmcdona/windows_timers_raw_dpc_offset
Windows: Fix raw Dpc offset calculation
2025-03-20 20:28:18 +00:00
David McDonald d097d6abeb Timers: convert general Exception to InvalidAddressException 2025-03-20 15:18:08 -05:00
David McDonald c4589a51d5 Timers: Adds debug log statement to catch-all exception 2025-03-20 15:13:26 -05:00
David McDonald 1e175b5d3b Objects: rework new get_raw_value() method
Per code review recommendations, splits the `_unmarshall` classmethod
into two components, one of which retrieves the raw value, and the other
that returns the masked pointer. The `get_raw_value` method now calls
the `_get_raw_value` classmethod using its instance information.
2025-03-20 15:11:37 -05:00
David McDonald 144fd3139a Framework: Minor version bump
Made an additive change to `Pointer` by adding the `get_raw_value()`
method, so bumping the minor version here. The `get_raw_dpc()` method
was removed from the `KTIMER` extension class, which is currently
unversioned.
2025-03-20 14:38:19 -05:00
David McDonald a8ea3aae01 Extensions: Removes the get_raw_dpc method from KTIMER
This removes the `get_raw_dpc` method from the `KTIMER` extension class.
This method was inaccurate in that it actually returns the masked
pointer value instead of the full 64-bit value encoded in that member,
which is required in order to correctly decode the 'real' pointer.

The invocation of `get_raw_dpc()` was replaced with
`self.Dpc.get_raw_value()`, which was added in the previous commit.
2025-03-20 14:32:04 -05:00
David McDonald 7b9fb91672 Objects: create get_raw_value() method for Pointer
This creates a `get_raw_value()` method for the `Pointer` class that
allows users to access the raw (unmasked) value of a pointer. This was
required in order to decode the encoded `Dpc` pointer that is part of
the `_KTIMER` Windows type. Addition of this type was favored over a
cast to `unsigned long` or `unsigned long long` due to the potential for
future instability of this type due to compiler changes.

See https://github.com/volatilityfoundation/volatility3/issues/1041 for
further discussion around the conversion of `log unsigned int` to
`unsigned long` in `clang`.

See https://github.com/volatilityfoundation/volatility3/pull/1177#discussion_r1650049299
for the original discussion around how to access this pointer in the
`Timers` plugin.
2025-03-20 14:23:24 -05:00
ikelosandGitHub 369f37ec43 Merge pull request #1727 from volatilityfoundation/kallsyms_fixes_round2
Hopefully final round of kallsym fixes
2025-03-20 18:26:23 +00:00
Andrew Case 548657c309 Change None check to remove False booleans 2025-03-20 15:02:22 +00:00
ikelosandGitHub 69f3707eb3 Merge pull request #1726 from volatilityfoundation/add_lkm_load_parameters
Add the recovery and reporting of LKM load parameters
2025-03-20 00:28:55 +00:00
Andrew Case 508cbd3a17 Fix function name 2025-03-19 23:51:29 +00:00
Andrew Case 741a4ea809 Hopefully final round of kallsym fixes 2025-03-19 23:49:45 +00:00
Andrew Case bfe50889b0 Add the recovery and reporting of LKM load parameters 2025-03-19 17:32:09 -05:00
David McDonald 2795c7cdd2 Windows: Fix raw Dpc offset calculation
The original code was still returning this as a pointer that ended up
dereferenced in later steps. However, this pointer value actually needs
to be cast to an `unsigned long long` and decoded first.
2025-03-19 15:45:26 -05:00
ikelosandGitHub bd5fb7d611 Merge pull request #1719 from volatilityfoundation/linux_unifiy_module_gathering_output
Create versioned parent class for all plugins that enumerate Linux ke…
2025-03-18 08:18:15 +00:00
Andrew Case 06a4c56395 Update for new accessing method 2025-03-17 20:15:18 -05:00
Andrew Case 0667a40836 Removed unused import 2025-03-17 19:06:02 -05:00
Andrew Case 93be148534 Change how the inheritance is performed 2025-03-17 19:04:02 -05:00
Andrew Case 00c4a13567 remove errant space 2025-03-17 18:58:55 -05:00
Andrew Case f906bde338 change lmsod call 2025-03-17 18:56:54 -05:00
Andrew Case 971f06996b bump version on kallsyms 2025-03-17 18:56:49 -05:00
Andrew Case 7146b45fa7 Create versioned parent class for all plugins that enumerate Linux kernel modules. Convert plugins to new method. 2025-03-17 18:56:05 -05:00
ikelosandGitHub 93e2072509 Merge pull request #1723 from volatilityfoundation/fix_extension_checks
Add needed checks to prevent backtraces in ELF parsing
2025-03-17 23:53:01 +00:00
ikelosandGitHub 03bc1c79ed Merge pull request #1722 from volatilityfoundation/kallsyms_fixes_and_remove_deprecated_calls
Fix bugs in kallsyms and the related pscallstack found in testing and…
2025-03-17 23:52:51 +00:00