Commit Graph
229 Commits
Author SHA1 Message Date
Mike Auty f584be8d18 Fix up the linux symbol caching code. 2018-09-03 21:39:48 +01:00
Mike Auty 5668f271df Fix issue when handling zip files on windows. 2018-09-02 00:13:33 +01:00
Mike Auty dff7e6d6df Add in support for specific symbol directories. 2018-09-01 21:57:49 +01:00
superponibleandikelos 26a4eb66d9 move import to the top 2018-08-30 10:57:18 +01:00
superponibleandikelos f5e075ab72 change comment to docstring 2018-08-30 10:57:18 +01:00
superponibleandikelos eb9a426760 switch enum.Enum to enum.IntEnum 2018-08-30 10:57:18 +01:00
Dave Lassalleandikelos c676f17fc8 refs #39 - update _CM_KEY_BODY.get_full_key_name() 2018-08-30 10:57:18 +01:00
Mike Auty 3a6b4ad35c Add in the has_member method for objects and templates. 2018-08-29 22:54:56 +01:00
Dave Lassalleandikelos c7e0ff9fa0 docstring and comment about get() vs _missing_() 2018-08-29 21:51:52 +01:00
Dave Lassalleandikelos 0d12a6dbf3 alternative to RegValueTypes enum in lieu of _missing_() 2018-08-29 21:51:52 +01:00
Dave Lassalleandikelos 32bcdf2ebc add userassist types to registry.json 2018-08-29 21:51:52 +01:00
Mike Auty 0f08432aa5 Refactor Symbol interface to SymbolInterface. 2018-08-09 14:28:08 +01:00
Mike Auty 99f8859549 It turns out that cloning native_templates was unnecessary or slow. Fix and document why clearly. 2018-08-09 12:49:51 +01:00
Mike Auty e19ac82480 Improve generator documentation. 2018-08-05 16:26:27 +01:00
Mike Auty d08c29ffab Improve style to use default iterators rather than explicit ones. 2018-08-05 16:18:53 +01:00
Mike Auty b1d46f843b Convert documentation to napoleon/Google format docstrings. 2018-08-05 15:52:12 +01:00
Mike Auty 4897b7ab81 Fix up some typing errors. 2018-07-22 13:19:20 +01:00
Mike Auty 2f3f291e53 Fix up missing parameter in symbol_space. 2018-07-19 09:54:56 +01:00
Mike Auty c0ec52822b Add some typing fixes. 2018-06-16 14:19:36 +01:00
Mike Auty 86c5302c99 _missing_ was a python-3.6 feature. 2018-06-16 12:36:00 +01:00
Dave Lassalleandikelos 5467c1c5e3 prevent from halting on an unknown registry value type 2018-06-16 09:54:45 +01:00
Dave Lassalleandikelos 218b1fd37c use masked length to extract data 2018-06-16 09:54:45 +01:00
Dave Lassalleandikelos 6cfd3b6499 fix typo in debug statement 2018-06-16 09:54:45 +01:00
Michael LighandMike Auty 76f5d35499 update _KDDEBUGGER_DATA64.get_build_lab() to not reference "nt_symbols" 2018-06-12 08:41:37 +01:00
Michael LighandMike Auty ae9d7dbc86 use *args and **kwargs when inheriting from IntermediateSymbolTable 2018-06-12 08:41:37 +01:00
Michael LighandMike Auty fb57e2c5f2 wininfo, procdump, dlldump, and json for pe & kdbg 2018-06-12 08:40:21 +01:00
Mike Auty 2cbd444603 Add in symbol table address masker. 2018-06-06 23:12:46 +01:00
Mike Auty 253304270b Ensure we can add native_types when we create tables. 2018-06-06 00:42:23 +01:00
Mike Auty 36dee38a9e Leave pointer out of the default types (since it needs an appropriate size). 2018-06-05 21:46:02 +01:00
Mike Auty 2dc3d2928d Fix more typing issues. 2018-06-04 23:28:26 +01:00
Dave Lassalleandikelos abfcdba524 add Windows 10 Registry process support 2018-06-04 20:17:28 +01:00
Mike Auty 7a52ac9deb Fix a large number of typing issues.
There are several instances where mypy didn't detect

if blah is not None:
    blah = thing

and so were rewritten as:

blah = blah or thing
2018-06-04 01:25:02 +01:00
Mike Auty 6a6acd2dcc Move the table_mapping parameter to avoid disrupting the previous interface. 2018-05-30 18:37:29 +01:00
Mike Auty 33b2c9522d Add in support for ISF.create to handle table_mappings. 2018-05-23 22:26:52 +01:00
Mike Auty a5df5372f5 Add in table_mapping through the ISF classes. 2018-05-23 22:23:32 +01:00
Mike Auty 665db0017e Don't count the volatile bit when checking things are outside the hive maximum address. 2018-05-21 18:02:48 +01:00
Mike Auty 2cb5435911 Change the signature for add_process_layer to match linux. 2018-05-07 17:45:40 +01:00
awaltersandikelos e8f64664a8 Initial changes based on @ikelos review. Also updated crash structs. 2018-05-02 20:10:14 +01:00
awaltersandikelos 6eeafbc391 Windows Crash Layer 2018-05-02 20:10:14 +01:00
Mike Auty 556fa29ada Deprecate/remove 'provides' attribute. 2018-04-26 12:31:33 +01:00
Mike Auty 623180ddbd Make many typing fixes, based on mypy-0.590. 2018-04-22 20:45:59 +01:00
Mike Auty 6402c94078 Rework IntermediateSymbolFile loading to a classmethod. 2018-04-12 15:15:25 +01:00
Michael Ligh aa774ffca6 Refs #21 fix vadinfo's get_private_memory() on 10.0.14393.x 2018-04-11 09:24:02 -05:00
Dave Lassalleandikelos 1ae43783aa create utility function for converting windows timestamps 2018-03-21 18:42:38 +00:00
Mike Auty 2522d588ea Pylinting and typing fix. 2018-03-21 17:04:10 +00:00
Mike Auty e133509ea8 Fix broken type resolution
The introduction of symbol resolution required subresolving "unnamed"
(symbol named) types.  The resolution system was changed to pass
constructed objects rather than names, which prevented the referencing
from working properly.  This commit changes that bit back and creates a
temporary *type* in the _resolved list for the symbol, then restores
whatever was there before.

We restore it so that people don't get used to looking up symbols using
get_type (we may revisit this decision).
2018-03-21 15:32:09 +00:00
Mike Auty 66b64e5dfa Ensure symbol types are recursively resolved. 2018-03-20 23:53:13 +00:00
Michael Lighandikelos 205af99a3e Rev2 after rev1 comments 2018-03-19 22:35:00 +00:00
Michael Lighandikelos 8282df5893 Initial versions of vadinfo and vaddump 2018-03-19 22:35:00 +00:00
Mike Auty 1a80dbf935 Change Unparsable to NotApplicable for situations we expect. 2018-03-10 21:43:46 +00:00