Commit Graph
146 Commits
Author SHA1 Message Date
Mike Auty a3caf39097 Use a mapping to determine kind to class. 2019-08-31 12:57:53 +01:00
Mike Auty 35dbdfc69d Add in PluginRequirement for proc_maps plugin. 2019-08-27 23:35:19 +01:00
Mike Auty a9853eca50 Fix the copyright headers (and yapf) in the mac plugins. 2019-08-27 23:34:06 +01:00
Andrew Caseandikelos 6b4c13089d add mac_proc_maps 2019-08-27 23:31:01 +01:00
Andrew Caseandikelos 07ece011a3 Add mac_tasks 2019-08-27 23:28:51 +01:00
Mike Auty 9cde94bceb Change the license blurb on all files. 2019-08-27 23:11:00 +01:00
Mike Auty 42b2fb120a Swap TranslationLayerInterface decendents over to LinearMappedLayers 2019-08-27 21:09:13 +01:00
Mike Auty 71bb54379b Refactor the plugin versioning to be simpler to define. 2019-08-27 21:08:29 +01:00
Mike Auty 47c349e240 Add plugin requirements for all plugins. 2019-08-27 21:08:29 +01:00
Mike Auty 58dffe8795 Fix typos from the rebase, and add documentation. 2019-08-27 21:08:29 +01:00
Mike Auty a58f064ea8 Rework how the plugin_version is checked. 2019-08-27 21:08:29 +01:00
Mike Auty 11fc8654e3 Initial attempt at plugin versioning.
So this allows people to alter the APIs for their plugins and allows
plugins to verify the API is compatible with the one they expect.

It adds a version property to Plugin classes, and has a SemVer checking
method which can be called from other plugins to verify a plugin against
a particular version.
2019-08-27 21:08:29 +01:00
Mike Auty 6fc12e9b01 Make sure options are specific to each plugin.
So this feels like a contentious decision.  It'd be awesome to have the
options for the methods stored along-side the methods themselves.

The downside with this is that the thing accessing the configuration
data is always the plugin, so it's the plugin that must have requested
the configuration option.  This is also important in case the
description of the configuration option needs modifying for clarity or
providing context for how it will be used.

If the interface changes, all plugins calling the plugin methods will
need updating, so the config options can be updated if necessary.
2019-08-23 21:41:50 +01:00
Mike Auty d0b0a96ac1 Refactor the run_plugin method to more accurate construct_plugin. 2019-08-20 00:13:00 +01:00
Mike Auty c0f650ba78 Ensure Mac plugins are documented and add complex tasks documentation. 2019-08-18 22:35:34 +01:00
Mike Auty 37e13321f9 Fix warnings when generated documentation. 2019-08-18 18:30:44 +01:00
Mike Auty 57510803d5 Fix up an issue when removing PoolHeaderSymbolTable. 2019-08-18 01:19:34 +01:00
Mike Auty 1082429aab Don't use a separate symbol table class just to add a class override. 2019-08-17 23:20:46 +01:00
Mike Auty 35d8faae83 Add in exception throwing if case of no valid response. 2019-08-15 22:09:41 +01:00
Mike Auty 433e40a606 Support some middling versions of windows 10 in virtmap. 2019-08-15 21:49:21 +01:00
Mike Auty 287c7ce0b0 Minor fixes for virtmap given the recent module refactoring. 2019-08-15 21:05:49 +01:00
Mike Auty 8ccf8b045d Add in first draft of virtmap plugin. 2019-08-14 20:53:45 +01:00
Mike Auty 5db6ade2ea Change object_type parameter for object_from_symbol. 2019-08-14 20:50:42 +01:00
Mike Auty be27aab8ae Refactor symbol to object_type (so it doesn't shadow builtin type). 2019-08-14 20:50:42 +01:00
Mike Auty 18283ab410 Move to an object_from_symbol model
Note: creation of enumerations can be done using Context.object, which
should allow reference of enumeration members by normal type objects.

If it turns out enumerations are never referenced from types, we can
easily remove the try/except in the Module.object method.
2019-08-14 20:50:42 +01:00
Mike Auty 5362e2094e Initial attempt at cleaning up the API
Context.object accepts a template or a string name (and now a type
flag).  Module.object only accepts a string (because a template already
has most of the stuff built in and might as well be passed to the
Context.object constructor).

The gotcha here is the absolute flag, which must now be set
appropriately in all cases *except* where the module is constructed
with an offset of 0 (whereby it will have no impact).
2019-08-14 20:50:42 +01:00
superponibleandikelos 0a5861350a use UnreadableValue 2019-08-13 20:37:46 +01:00
superponibleandikelos 3361d77d17 remove redundant log message 2019-08-13 20:37:46 +01:00
superponibleandikelos ef7e7fd905 only catch InvalidAddressException 2019-08-13 20:37:46 +01:00
Dave Lassalleandikelos 0e22eea58d improved exception handling in registry and printkey 2019-08-13 20:37:46 +01:00
Mike Auty 8ddfe8ce16 Update plugins using the old PESymbolTable method 2019-08-09 00:49:05 +01:00
Mike Auty fbeab3608c Make we raise if the _POOL_HEADER type doesn't exist. 2019-08-08 01:09:56 +01:00
Mike Auty 253ce69fc9 Refactor poolscanner layer to move more into the parallel scanner. 2019-08-07 18:37:56 +01:00
Mike Auty 9ed1a5a5b6 The header is not dependent on the constraint, so only construct it once. 2019-08-07 16:33:13 +01:00
Mike Auty 164079c203 Casting will use the original object's symbol_table if none is provided. 2019-07-23 00:46:09 +01:00
Mike Auty e78839b5e9 DON'T import from framework.plugins. It won't work. 2019-07-16 00:37:23 +01:00
Analystandikelos 6e4fa57421 move type_classes to dictionaries stored in their modules rather than separate classes (see 81d3293) 2019-07-15 21:16:32 +01:00
Analystandikelos 79c7c6df95 change context.memory to context.layers per 272224a 2019-07-15 21:16:32 +01:00
Analystandikelos a26b9bb57d don't require pslist.PsList.list_processes_filter_requirements - it introduces --pid to the plugin's arguments 2019-07-15 21:16:32 +01:00
Analystandikelos e1d160baee fix typing for get_vad_maps() 2019-07-15 21:16:32 +01:00
Analystandikelos 20d7152050 remove unnecessary debugging 2019-07-15 21:16:32 +01:00
Analystandikelos 3ea0432ee4 fix the typing for get_record_tuple() 2019-07-15 21:16:32 +01:00
Analystandikelos e6ae049d18 add svcscan and associated types 2019-07-15 21:16:32 +01:00
Mike Auty f5615e28f6 Fix up more typing discrepancies. 2019-07-15 17:43:43 +01:00
Mike Auty 272224a1b0 Refactor all references to Context.memory to Context.layers. 2019-07-07 17:42:51 +01:00
Mike Auty ef28a9b733 Apparently, it wasn't in 3.5, but it throws type-checking errors
Python3.6 introduced it, but annoying the type-checker realizes that
we're using it like any int (ie, A | B) and throws a wobbly.  Really
want to see the back of python3.5...

Revert "IntFlag is in python-3.5 by default, it's just if the enum34 package is installed that problems happen."

This reverts commit 17a0e1eac8.
2019-06-28 15:31:59 +01:00
Mike Auty 17a0e1eac8 IntFlag is in python-3.5 by default, it's just if the enum34 package is installed that problems happen. 2019-06-28 15:29:40 +01:00
Mike Auty 81d3293414 Move type_classes to dictionaries stored in their modules rather than separate tables. 2019-05-29 22:14:38 +01:00
Mike Auty 6a12361977 Fix up minor typo in info plugin. 2019-05-29 22:14:25 +01:00
Andrew Case 2a8a1523e5 Mac - add lsof plugin 2019-05-29 14:49:55 -05:00