Mike Auty
f34958a16d
Poolscanner: Add necessary exception handling.
2019-12-04 22:11:42 +00:00
Mike Auty
386f94d9ee
Pool: Make object_header type checking the plugin's responsibility.
2019-12-04 22:11:42 +00:00
Mike Auty
8691c68604
Pool: Refactor pool extension to its own file.
2019-12-04 22:11:42 +00:00
Michael Ligh and ikelos
d0f9cf9a2f
refs #139 use _EPROCESS.ControlFlowGuardEnabled to distinguish between windows 10 <= 15063 versus >= 16299
2019-12-04 21:19:19 +00:00
Mike Auty
b6d807ff51
Poolscanner: Document the typing issue of python3.5's IntEnum over IntFlag
2019-11-27 11:30:14 +00:00
Mike Auty
b0b868d79c
Typing: General typing fixes across the tree
2019-11-27 11:30:14 +00:00
Mike Auty
31ddbaaa2e
Typing: Fix python3 format string/byte output issues
2019-11-27 11:30:14 +00:00
Mike Auty
249c3ec223
Svcscan: Ensure or later checks are done in order.
...
Relates to issue 139.
2019-11-18 20:57:34 +00:00
Mike Auty
b99ace86fb
Tidy up exceptions to be more accurate.
2019-11-13 19:58:14 +00:00
Mike Auty
40fcdf9469
exceptions: SymbolErrors now contain specific information
2019-11-13 19:27:00 +00:00
doomedraven and ikelos
4543b0af33
Update vaddump.py
2019-11-13 18:54:19 +00:00
doomedraven and ikelos
97f670ec79
simplify vad dump to be used by other plugins
2019-11-13 18:54:19 +00:00
Mike Auty
face38436e
layers: Fix up uses of is_valid.
2019-11-12 09:09:51 +00:00
Mike Auty
23b14b772a
Poolscanner: Fix error in index checking.
2019-11-09 00:17:07 +00:00
Mike Auty
ee31ece006
Fix a logging on add_process_layer exceptions.
...
There were a number of issues with commit 3df5e995 that was applied in
haste (notably, that exceptions wasn't imported in several cases, which
would break the code if it were ever run).
We now give debugging output when a process can't be constructed and
provide as much available information as possible.
Two unused lines were also removed from verinfo.
2019-11-03 23:15:38 +00:00
Mike Auty
73aa73f30e
Ensure we test None using is rather than ==.
2019-11-03 22:46:20 +00:00
Mike Auty
4457bcaee0
vadyarascan: Ensure we scan the right layer
...
This patch ensures we scan the vad segments within the correct layer
(the process layer, not the kernel layer) and lists the pid in the
output.
2019-10-31 19:15:02 +00:00
Mike Auty
27a291cf61
Remove the erronious print statement, which should be a vollog message if needed.
2019-10-18 08:39:56 -04:00
Mike Auty
0be9061989
Tidy up commit e0097ac.
2019-10-18 08:38:17 -04:00
atcuno
3df5e9957e
Windows - add missing add_process_layer exception handling in a few plugins
2019-10-17 11:47:19 -04:00
atcuno
e0097ac9c1
Windows - protect handles from smear
2019-10-17 11:03:48 -04:00
atcuno
2e329d1106
Windows - add exception handling around is_valid in callbacks
2019-10-17 10:22:06 -04:00
Mike Auty
3784c9aff6
Fix up missing/inaccurate plugin description strings.
2019-10-03 01:05:57 +01:00
Mike Auty
3b656e337a
Update windows extensions to ensure they're documented.
2019-10-02 20:25:54 +01:00
Mike Auty
10a379b0ee
Make 'import as' consistent and ensure proper plugin dependencies.
2019-10-02 01:25:03 +01:00
Mike Auty
9a17beb77f
Ensure consistency of importing interfaces.
2019-10-02 01:18:46 +01:00
Mike Auty
8e10f4e3d1
Clarify handles error message.
2019-10-02 00:06:25 +01:00
Mike Auty
9ac622afa0
Fix up import style to be consistent.
2019-10-01 23:46:02 +01:00
Mike Auty
153b3b7d39
Make sure we catch the most general exception for what we mean.
2019-09-27 11:19:53 +01:00
Mike Auty
679a0eabc2
Tidy Exceptions and ensure LayerExceptions are passed a layer name.
2019-09-26 15:44:36 +01:00
Mike Auty
e0b9d72c84
Update the license URL and LICENSE.txt
2019-09-25 21:44:05 +01:00
Mike Auty
72567e1c50
Yapf-0.28.0 rerun across the whole codebase.
2019-09-21 21:08:23 +01:00
Mike Auty
d2b892cf94
Fix up docstring errors in documentation build
2019-09-19 23:00:37 +01:00
Mike Auty
1f9605abf7
Revert "Fix warnings when generated documentation."
...
This actually broke autodoc generation and wasn't accurate. The
documentation warnings may have to stay for now.
This reverts commit 37e13321f9 .
2019-09-17 18:32:44 +01:00
Mike Auty
7efe19224e
Make several small typing information fixes.
2019-09-17 18:01:11 +01:00
Mike Auty
33451967b2
Typing fixes for virtmap and remove extranious exception.
2019-09-17 17:58:47 +01:00
superponible and ikelos
ae8822dddf
check if hive offset is valid before yielding
2019-09-17 16:59:50 +01:00
superponible and ikelos
2fa9e6b84d
fix typo in comment
2019-09-17 16:59:50 +01:00
superponible and ikelos
508a9148ed
catch InvalidAddressException when creating RegistryHive
2019-09-17 16:59:50 +01:00
superponible and ikelos
36f5e47d5b
fix up docstrings to match yield values
2019-09-17 16:59:50 +01:00
Mike Auty
c6cdbc7342
Move the hive_iterator to HiveList, since it's more intuitively where it should live.
2019-09-17 16:59:50 +01:00
Mike Auty
b292188319
Update userassist to use the new printkey API.
2019-09-17 16:59:50 +01:00
Mike Auty
46c047b7b3
Update API slightly to return objects not strings.
2019-09-17 16:59:50 +01:00
Mike Auty
b413e4a13d
Refactor printkey to be more usable from other plugins.
2019-09-17 16:59:50 +01:00
Mike Auty
10cf65fb60
Add in better documentation for callbacks.
2019-09-10 00:43:44 +01:00
Michael Ligh and ikelos
4e3db7a3de
add PluginRequirements for ssdt and svcscan. add missing _version to svcscan
2019-09-08 16:08:48 +01:00
Michael Ligh and ikelos
1d7f2a9582
use ntkrnlmp.object() instead of context.object(). remove config_path argument to list* functions
2019-09-08 16:08:48 +01:00
Michael Ligh and ikelos
50548bac73
reformat with yapf
2019-09-08 16:08:48 +01:00
Michael Ligh and ikelos
e71b72b3a7
add the windows callbacks plugin
2019-09-08 16:08:48 +01:00
Mike Auty
421af88c29
Classmethod make_subconfig so other classmethods can use it.
2019-09-08 14:50:48 +01:00