ikelos and GitHub
962146b420
Merge pull request #677 from Digitalisx/fix/unuse-import
...
Remove Windows Symbol Initialize duplicate import.
2022-03-16 20:50:38 +00:00
Mike Auty
cb8a1fb90c
CLI: Fail on overwriting a config file
2022-03-16 20:36:26 +00:00
Mike Auty
a6217784ce
Windows: Tidy up hashdump plugin
...
Shouldn't have merged this with mention of profiles.
Also fixes #678 .
2022-03-16 20:12:22 +00:00
Donghyun Kim
02394f89a8
Add return type hint, Add full option, Update yield data
2022-03-17 02:22:51 +09:00
Donghyun Kim
b02783baf1
Remove index initialize, __str__ method by partition entry logic update
2022-03-16 22:37:44 +09:00
Donghyun Kim
1645443d3b
Remove Hexdump Column
2022-03-16 22:30:57 +09:00
Donghyun Kim
3ab3fa3ed8
Remove Windows Symbol Initialize unuse import
2022-03-16 17:39:06 +09:00
Donghyun Kim and GitHub
39f044e9a7
Merge branch 'volatilityfoundation:develop' into feature/mbr-parser
2022-03-16 13:44:59 +09:00
Mike Auty
0f4f4f2b3a
CLI: Add configuration option for blatting over config files
2022-03-16 01:41:18 +00:00
Mike Auty
eb38756dbe
CLI: Add deprecation warning to --write-config
2022-03-16 01:35:47 +00:00
Mike Auty
fa723ec134
CLI: Implement specifying a config name to write
2022-03-16 01:29:20 +00:00
ikelos and GitHub
7d17c191e5
Merge pull request #675 from paulkermann/bugfix/is_vad_empty
...
Windows Malfind is_vad_empty error
2022-03-15 12:31:56 +00:00
Paul Kermann
7c89fc3f07
bug fix :(
2022-03-15 14:22:36 +02:00
ikelos and GitHub
e1c157eb71
Merge pull request #673 from volatilityfoundation/feature/better-csv-support
...
Renderers: Use built-in python CSV support
2022-03-15 09:01:28 +00:00
Donghyun Kim and GitHub
8aeaa83e6f
Merge branch 'volatilityfoundation:develop' into feature/mbr-parser
2022-03-14 10:57:29 +09:00
Donghyun Kim
f97348616f
Define 'all_zero' default value, Update output column name
2022-03-14 09:47:34 +09:00
ikelos and GitHub
6c84568031
Merge pull request #660 from volatilityfoundation/feature/better-dtb-detection
...
Feature/better dtb detection
2022-03-13 22:05:31 +00:00
Mike Auty
0de8c645a4
Renderers: Add column headers for CSV
2022-03-13 21:20:04 +00:00
Mike Auty
eba7ad1c0d
Renderers: Use built-in python CSV support
2022-03-13 21:13:25 +00:00
Donghyun Kim and GitHub
54a93a12f5
Merge branch 'volatilityfoundation:develop' into feature/mbr-parser
2022-03-11 12:49:04 +09:00
Donghyun Kim
4e4143223a
Merge branch 'feature/mbr-parser' of https://github.com/Digitalisx/volatility3 into feature/mbr-parser
2022-03-10 13:52:07 +09:00
Donghyun Kim
1b71aad366
Update BootableFlag Symbol
2022-03-10 13:51:52 +09:00
Donghyun Kim
a35fa04f00
Update BootableFlag Symbol
2022-03-10 01:12:49 +09:00
Donghyun Kim
7c00b2f4ea
Add Code Comment, Hash Funtion, Exception
2022-03-10 00:13:46 +09:00
Donghyun Kim
b6a14e6de4
Add Symbol code comment, hash
2022-03-09 23:42:21 +09:00
ikelos and GitHub
9aa0b5d6f7
Merge pull request #666 from volatilityfoundation/issues/issue631
...
Layers: Better checks on PAE page tables
2022-03-09 09:03:11 +00:00
Donghyun Kim
5de6462fae
Restore mft.json
2022-03-09 17:09:36 +09:00
Donghyun Kim
b01333115b
__str__ Formatting
2022-03-09 17:08:27 +09:00
Donghyun Kim
e0a512e9ff
Add EOF of MBR Symbol
2022-03-09 16:13:25 +09:00
Donghyun Kim
eda765d61d
Update MBR Partition Entry Object Function
2022-03-09 16:12:32 +09:00
Donghyun Kim
7ff2572bec
Merge branch 'feature/mbr-parser' of https://github.com/Digitalisx/volatility3 into feature/mbr-parser
2022-03-09 13:28:01 +09:00
Donghyun Kim
acc3f6f352
Update Symbol Table, Load Physical Layer
2022-03-09 13:27:53 +09:00
Donghyun Kim and GitHub
9eb93bb949
Merge branch 'volatilityfoundation:develop' into feature/mbr-parser
2022-03-09 08:50:26 +09:00
ikelos and GitHub
b191626b0a
Merge pull request #669 from Digitalisx/fix/typo-error
...
Fix Typo Error for some plugins, documents
2022-03-08 19:58:31 +00:00
Donghyun Kim
18770d0cd3
Fix glossary.rst Typo Error
2022-03-09 02:09:47 +09:00
Donghyun Kim
6c1fe42a37
Fix Docs, Framework, Windows Plugin Typo Error
2022-03-09 01:53:04 +09:00
Samuel Zurowski
4087236957
Changed named and used thread_group instead to ensure all threads are grabbed
2022-03-07 19:18:17 -05:00
Donghyun Kim
34a732a4f0
Fix Object Typo Error
2022-03-07 14:00:03 +09:00
Donghyun Kim
a1023e51f5
Fix Renderes, Scanners, MFT Symbol Typo Error
2022-03-07 13:54:35 +09:00
Samuel Zurowski
68903c63df
Added task_struct function to get each task_struct from the thread_nodes structure
2022-03-06 20:20:24 -05:00
Mike Auty
244751e9ae
Layers: Better checks on PAE page tables
...
This checks that the very top level table points to the next four pages,
as we'd expected in general. This relies on the same assumptions as the
existing PAE detection did, ie that the PAE page_map maps the next four
pages immediately.
Previously we didn't check that the top page was valid, once we found
the self-referential pointer. This adds in an appropriate check to
reduce false positives.
Closes #631 .
2022-03-06 18:48:00 +00:00
Donghyun Kim
7570e82786
Configuration Yara Rules
2022-03-05 17:47:37 +09:00
Donghyun Kim
06961ce537
Initialize MBR Parser
2022-03-05 16:32:38 +09:00
Donghyun Kim
639f87a0a4
Remove Tab
2022-03-05 16:29:40 +09:00
Donghyun Kim
f060562b27
Rebase
2022-03-05 16:29:09 +09:00
Donghyun Kim
ad1ef807e7
Context Typo Error, MFT Symbol JSON Prettier
2022-03-05 16:27:07 +09:00
Donghyun Kim and GitHub
6cb2b2bf84
Merge branch 'volatilityfoundation:develop' into develop
2022-03-05 15:43:38 +09:00
Mike Auty
670401eac7
Windows: Test unicode strings for length 0
...
In some tests we were checking whether asking for the string value threw
an InvalidAddressException through an error as to whether we should look
elsewhere for the data. As of commit 265b2825 we now treat 0-length
strings as valid (as per #652 ), meaning we need to check for length 0
as well as invalid pointers.
If this crops up often, we may need to revisit the decision to make sure
its in keeping with how windows treats zero length strings, but for now
we only did it once for registry keys.
Closes #665
2022-03-03 20:35:39 +00:00
Donghyun Kim
49308eb18d
Restore PR
2022-03-03 02:03:31 +09:00
Donghyun Kim
dae8860577
Restore PR
2022-03-03 02:02:43 +09:00