6545 Commits
Author SHA1 Message Date
eve e55ab3313f Linux: update tests for sockscan 2025-04-24 09:16:23 +01:00
eve 1a57a66ce6 Linux: update sockstat ruff issue with f-string using no placeholders 2025-04-24 09:11:36 +01:00
eve 5e549b2d92 Linux: update sockstat requirements 2025-04-24 09:10:51 +01:00
EveandGitHub 40144e7c71 Merge branch 'develop' into linux_sockscan 2025-04-24 09:05:26 +01:00
95c54351f0 Update volatility3/framework/plugins/linux/sockscan.py
Co-authored-by: ikelos <ikelos@users.noreply.github.com>
2025-04-24 09:01:53 +01:00
0fbe03912e Update volatility3/framework/plugins/linux/sockscan.py
Co-authored-by: ikelos <ikelos@users.noreply.github.com>
2025-04-24 09:01:42 +01:00
dcded3a1fc Update test/test_volatility.py
Co-authored-by: ikelos <ikelos@users.noreply.github.com>
2025-04-24 09:00:50 +01:00
David McDonald bceae67d43 Windows Handles: Update dependents
This updates the plugins that depend on `Handles` with the correct
required version number, as well as calls to the new handles
classmethods where needed.
2025-04-23 11:33:58 -05:00
David McDonald bb91d688cb Windows Handles: Convert to classmethods
A lot of functionality in this plugin class was using instance methods
instead of classmethods; this refactors the plugin to use classmethods
instead of instance methods for consistency with the rest of the
framework, and bumps the plugin major version to 4.0.0.
2025-04-23 11:33:58 -05:00
David McDonald 2641e5fc41 ShimcacheMem: Fix exc getting module name
`module.BaseDll.String` can raise an `InvalidAddressException`, this
catches it and continues through the loop.
2025-04-21 15:50:57 -05:00
Dave Lassalle 094ba8e269 #1780 - black and ruff fixes 2025-04-17 16:44:22 -05:00
Dave Lassalle 4d19181848 #1780 - add LoadCount to dlllist output 2025-04-17 16:42:17 -05:00
ikelosandGitHub 63f7cbd447 Merge pull request #1779 from j-t-1/svcdiff
Amend SvcDiff comments at top of file
2025-04-17 21:10:31 +01:00
j-t-1andGitHub ff5d736f94 Amend SvcDiff comments at top of file
Previously contained information about Skeleton_Key_Check, change this to be about SvcDiff.
2025-04-17 20:35:38 +01:00
ikelosandGitHub fa73298e0f Merge pull request #1579 from volatilityfoundation/feature/coding-style
Feature/coding style
2025-04-16 10:19:26 +01:00
ikelosandGitHub 65a02d961e Merge pull request #1764 from volatilityfoundation/issues/make-quickstart-quicker
Documentation: Improve the readme to make quickstart the first thing …
2025-04-16 10:18:22 +01:00
ikelosandGitHub 6eb95ca4dc Merge pull request #1778 from Abyss-W4tcher/qemu_layer_incomplete_requirements
Make QEMU layer call parent's requirements
2025-04-15 23:50:44 +01:00
Abyss Watcher 4c6188766c black 2025-04-15 23:05:00 +02:00
Abyss Watcher 330e19f159 call parent get_requirements() 2025-04-15 23:04:49 +02:00
David McDonald 85ec26db91 Shimcachemem: Changes absent value return type
This is more appropriately set to `renderers.UnreadableValue` since it
is set when an `exceptions.InvalidAddressException` occurs.
2025-04-15 15:55:52 -05:00
David McDonald 4ce173e87a ShimcacheMem: Fix traceback in extension method
When performing the attribute checks for ListFlags.BlobBuffer, a pointer
dereference occurs implicitly that can trigger an
`exceptions.InvalidAddressException`. This wraps the checks in a
try/except block, and sets the value of `_exec_flag` to
`renderers.UnreadableValue` if one occurs.
2025-04-15 15:52:54 -05:00
ikelosandGitHub 2a16bf19d1 Merge pull request #1777 from volatilityfoundation/fix_thrdscan_tracebacks
ThrdScan: Fix tracebacks + filtering
2025-04-15 20:08:42 +01:00
David McDonald b04a498cd7 ThrdScan: Fix process filtering
This check was both causing an `InvalidAddressException` due to the
member access, while at the same time not being a useful check, since it
prevents VADs from being mapped in children of the `System` process.
2025-04-15 13:40:04 -05:00
David McDonald 537efa60e2 Thrdscan: Remove filtering based on VAD count
This was preventing enumeration of valid processes (confirmed by
disassembly of the start address/Win32 start address). Heuristic-based
filtering should probably be left to consumers of the APIs.
2025-04-15 13:39:58 -05:00
ikelosandGitHub 923ea92cf3 Merge pull request #1772 from volatilityfoundation/fix_symlink_scanning
Poolscanners: Fix symlink pool types
2025-04-15 18:06:17 +01:00
ikelosandGitHub 8dae65ee3c Merge pull request #1769 from volatilityfoundation/inodepages/memory_usage
Linux pagecache.Files: Memory Usage
2025-04-15 17:18:00 +01:00
David McDonald 2199375dd5 Tests: Add symlinkscan specific test 2025-04-15 10:49:43 -05:00
David McDonald 32e9cee6dd Tests: Add Symlinkscan generic test
This should be enough to prevent serious regressions that break all
output.
2025-04-15 10:49:43 -05:00
David McDonald d745a62d7f PoolScanner: Patch version bump
Bumping the patch version due to bugfix.
2025-04-15 10:21:52 -05:00
David McDonald 02fbb3ce49 Poolscanners: Fix symlink pool types
Fixes regression introduced in #1632

Symbolic links are allocated in the paged pools, not non-paged. This was
causing us to miss symlinks across both pre and post win8 samples.
2025-04-15 10:14:58 -05:00
David McDonald d29be5cbde Linux MountInfo: Remove unneeded cast 2025-04-14 18:38:47 -05:00
David McDonald a236c0dd40 linux.pagecache.Files: Trim unneeded cast
Removes casts to `int` performed before checking set membership, since
the computed `__hash__` value will be the same for both the Python
primitive and the volatility `objects.Pointer`.
2025-04-14 18:30:19 -05:00
David McDonald 9ceec51b76 Pagecache: Add comments explaining cast
Adds a couple of comments explaining why we're doing a lossy conversion
to Python `int` (saving memory).
2025-04-14 18:25:17 -05:00
David McDonald c641690c53 Pagecache: revert cast to int
`dentry.vol.offset` is already a basic Python `int`.
2025-04-14 18:25:17 -05:00
David McDonald 3b723f8be3 Linux pagecache.Files: Memory Usage
Converts `objects.Pointer` to `int` before storing them in the set. This
should have a substantial impact on memory, similar to those in #1758
2025-04-14 18:25:17 -05:00
ikelosandGitHub df03d2220a Merge pull request #1771 from volatilityfoundation/framework/process_traversal_bugfix
Bugfix: Linux/Windows process traversal
2025-04-14 23:43:04 +01:00
David McDonald 2e206fe698 Add keywords to parameters 2025-04-14 17:17:02 -05:00
David McDonald 91e23e0c71 Bumps patch version for pslist plugins 2025-04-14 17:15:28 -05:00
David McDonald 8f9bebdc86 Linux PsList: Fix process list traversal
Fixes linux process listing by traversing the list backwards as well as
forwards while tracking seen process offsets to avoid duplicates.
2025-04-14 17:12:46 -05:00
David McDonald 17f9d218c9 Windows PsList: Fix list traversal logic
The traversal of `ActiveProcessLinks` from `PsActiveProcessHead` was
only being done in the forward direction; if for some reason
`PsActiveProcessHead` hasn't been updated to point at the 'current' list
head, entries in the backwards traversal direction will be missed.
2025-04-14 17:12:08 -05:00
ikelosandGitHub 745e148aba Merge pull request #1770 from volatilityfoundation/shimcachemem/bugfixes
ShimcacheMem: Various bugfixes
2025-04-14 18:24:52 +01:00
David McDonald 62bd41980b Shimcache: Use self.Path.vol.count instead of hardcoded value 2025-04-14 11:43:57 -05:00
David McDonald 1d4893156e Shimcache Extension: Fix logic error in exec_flag
Adds needed return statements in `exec_flag` method in order to avoid
`InvalidAddressException` when reading from invalid memory after an
`is_valid` check has already been performed.
2025-04-14 11:43:57 -05:00
David McDonald 079d2801f5 ShimcacheMem: Fix offset tracking
This fixes a bug in the plugin logic that causes valid entries to be
excluded in the following scenario:

- An entry is discovered but deemed invalid due to unreadable
  size/timestamps.
- The offset gets placed into the `seen` tracking set anyway
- Another entry (this time, with valid filesize/timestamps) with the
  same physical offset is encountered, but is skipped because this
  offset is already in the `seen` tracking set.

This updates the logic to only add the offset to the tracker if the
shimcache entry is valid.
2025-04-14 11:43:57 -05:00
David McDonald b80c52873b ShimcacheMem: Use address_to_string
Uses the new `address_to_string` utility function to read filepaths, in
case a filepath crosses a boundary to a swapped page.
2025-04-14 11:43:57 -05:00
David McDonald 87cc571fbb ShimcacheMem: Fix symbol table
These SHIM_CACHE_ENTRY offsets aren't correct - should be identical to
those in the other XP symbol tables.
2025-04-14 11:43:57 -05:00
ikelosandGitHub 4e0beda020 Merge pull request #1768 from volatilityfoundation/extensions/process_layer_caching
Extensions: Add cache decorators as appropriate
2025-04-14 17:31:54 +01:00
David McDonald 03e750648f Windows Extensions: remove lru_cache decorators
These don't offer enough upside to be worthwhile compared to the
decorators applied to the `add_process_layer` methods.
2025-04-14 09:20:32 -05:00
ikelosandGitHub 1b31357665 Merge pull request #1766 from volatilityfoundation/thrdscan/filtering_and_tracebacks
Windows ThrdScan: Thread filtering, type-hints and tracebacks
2025-04-13 15:55:43 +01:00
David McDonald c48ad901b0 Extensions: Add cache decorators as appropriate
I noticed that many plugins were creating duplicate per-process
translation layers - for instance, `windows.envars.Envars` was ending up
with > 30 process layers per process due to repeated calls to
`get_peb()`, which calls `add_process_space()` internally.

This adds `@functools.lru_cache` to the `get_peb()` and `get_peb32()`
methods on the `EPROCESS` extension, since these should only need to be
created once.

Also adds `@functools.lru_cache` to `add_process_space` to enable
reusing the same process address space, provided the same arguments are
passed to the `add_process_space()` method.
2025-04-10 14:57:46 -05:00