Mike Auty
a3caf39097
Use a mapping to determine kind to class.
2019-08-31 12:57:53 +01:00
Mike Auty
9cde94bceb
Change the license blurb on all files.
2019-08-27 23:11:00 +01:00
Mike Auty
42b2fb120a
Swap TranslationLayerInterface decendents over to LinearMappedLayers
2019-08-27 21:09:13 +01:00
Mike Auty
71bb54379b
Refactor the plugin versioning to be simpler to define.
2019-08-27 21:08:29 +01:00
Mike Auty
47c349e240
Add plugin requirements for all plugins.
2019-08-27 21:08:29 +01:00
Mike Auty
58dffe8795
Fix typos from the rebase, and add documentation.
2019-08-27 21:08:29 +01:00
Mike Auty
a58f064ea8
Rework how the plugin_version is checked.
2019-08-27 21:08:29 +01:00
Mike Auty
11fc8654e3
Initial attempt at plugin versioning.
...
So this allows people to alter the APIs for their plugins and allows
plugins to verify the API is compatible with the one they expect.
It adds a version property to Plugin classes, and has a SemVer checking
method which can be called from other plugins to verify a plugin against
a particular version.
2019-08-27 21:08:29 +01:00
Mike Auty
6fc12e9b01
Make sure options are specific to each plugin.
...
So this feels like a contentious decision. It'd be awesome to have the
options for the methods stored along-side the methods themselves.
The downside with this is that the thing accessing the configuration
data is always the plugin, so it's the plugin that must have requested
the configuration option. This is also important in case the
description of the configuration option needs modifying for clarity or
providing context for how it will be used.
If the interface changes, all plugins calling the plugin methods will
need updating, so the config options can be updated if necessary.
2019-08-23 21:41:50 +01:00
Mike Auty
37e13321f9
Fix warnings when generated documentation.
2019-08-18 18:30:44 +01:00
Mike Auty
57510803d5
Fix up an issue when removing PoolHeaderSymbolTable.
2019-08-18 01:19:34 +01:00
Mike Auty
1082429aab
Don't use a separate symbol table class just to add a class override.
2019-08-17 23:20:46 +01:00
Mike Auty
35d8faae83
Add in exception throwing if case of no valid response.
2019-08-15 22:09:41 +01:00
Mike Auty
433e40a606
Support some middling versions of windows 10 in virtmap.
2019-08-15 21:49:21 +01:00
Mike Auty
287c7ce0b0
Minor fixes for virtmap given the recent module refactoring.
2019-08-15 21:05:49 +01:00
Mike Auty
8ccf8b045d
Add in first draft of virtmap plugin.
2019-08-14 20:53:45 +01:00
Mike Auty
be27aab8ae
Refactor symbol to object_type (so it doesn't shadow builtin type).
2019-08-14 20:50:42 +01:00
Mike Auty
5362e2094e
Initial attempt at cleaning up the API
...
Context.object accepts a template or a string name (and now a type
flag). Module.object only accepts a string (because a template already
has most of the stuff built in and might as well be passed to the
Context.object constructor).
The gotcha here is the absolute flag, which must now be set
appropriately in all cases *except* where the module is constructed
with an offset of 0 (whereby it will have no impact).
2019-08-14 20:50:42 +01:00
superponible and ikelos
0a5861350a
use UnreadableValue
2019-08-13 20:37:46 +01:00
superponible and ikelos
3361d77d17
remove redundant log message
2019-08-13 20:37:46 +01:00
superponible and ikelos
ef7e7fd905
only catch InvalidAddressException
2019-08-13 20:37:46 +01:00
Dave Lassalle and ikelos
0e22eea58d
improved exception handling in registry and printkey
2019-08-13 20:37:46 +01:00
Mike Auty
8ddfe8ce16
Update plugins using the old PESymbolTable method
2019-08-09 00:49:05 +01:00
Mike Auty
fbeab3608c
Make we raise if the _POOL_HEADER type doesn't exist.
2019-08-08 01:09:56 +01:00
Mike Auty
253ce69fc9
Refactor poolscanner layer to move more into the parallel scanner.
2019-08-07 18:37:56 +01:00
Mike Auty
9ed1a5a5b6
The header is not dependent on the constraint, so only construct it once.
2019-08-07 16:33:13 +01:00
Mike Auty
164079c203
Casting will use the original object's symbol_table if none is provided.
2019-07-23 00:46:09 +01:00
Mike Auty
e78839b5e9
DON'T import from framework.plugins. It won't work.
2019-07-16 00:37:23 +01:00
Analyst and ikelos
6e4fa57421
move type_classes to dictionaries stored in their modules rather than separate classes (see 81d3293)
2019-07-15 21:16:32 +01:00
Analyst and ikelos
79c7c6df95
change context.memory to context.layers per 272224a
2019-07-15 21:16:32 +01:00
Analyst and ikelos
a26b9bb57d
don't require pslist.PsList.list_processes_filter_requirements - it introduces --pid to the plugin's arguments
2019-07-15 21:16:32 +01:00
Analyst and ikelos
e1d160baee
fix typing for get_vad_maps()
2019-07-15 21:16:32 +01:00
Analyst and ikelos
20d7152050
remove unnecessary debugging
2019-07-15 21:16:32 +01:00
Analyst and ikelos
3ea0432ee4
fix the typing for get_record_tuple()
2019-07-15 21:16:32 +01:00
Analyst and ikelos
e6ae049d18
add svcscan and associated types
2019-07-15 21:16:32 +01:00
Mike Auty
f5615e28f6
Fix up more typing discrepancies.
2019-07-15 17:43:43 +01:00
Mike Auty
272224a1b0
Refactor all references to Context.memory to Context.layers.
2019-07-07 17:42:51 +01:00
Mike Auty
ef28a9b733
Apparently, it wasn't in 3.5, but it throws type-checking errors
...
Python3.6 introduced it, but annoying the type-checker realizes that
we're using it like any int (ie, A | B) and throws a wobbly. Really
want to see the back of python3.5...
Revert "IntFlag is in python-3.5 by default, it's just if the enum34 package is installed that problems happen."
This reverts commit 17a0e1eac8 .
2019-06-28 15:31:59 +01:00
Mike Auty
17a0e1eac8
IntFlag is in python-3.5 by default, it's just if the enum34 package is installed that problems happen.
2019-06-28 15:29:40 +01:00
Mike Auty
81d3293414
Move type_classes to dictionaries stored in their modules rather than separate tables.
2019-05-29 22:14:38 +01:00
Mike Auty
6a12361977
Fix up minor typo in info plugin.
2019-05-29 22:14:25 +01:00
Analyst and ikelos
a90f3ed1a7
fixup an instance of is_windows_7 in poolscanner
2019-05-29 14:46:22 +01:00
Mike Auty
4ff137bc18
Fix up a is_windows_8_or_later call.
2019-05-29 14:46:22 +01:00
Mike Auty
38f249aef2
Change the os-distguisher to make it more flexible.
2019-05-29 14:46:22 +01:00
Mike Auty
867edc9501
Add in the os-distinguisher code.
2019-05-29 14:46:22 +01:00
Mike Auty
2b6007857e
Fix up type signature of filter_func for windows pslist.
2019-05-26 20:45:24 +01:00
Dave Lassalle and ikelos
61f9173bb6
initial hivescan plugin
2019-04-27 14:02:07 +01:00
Mike Auty
754b3f0bc6
Refactor create_filter to create_pid_filter.
2019-04-18 01:10:07 +01:00
Mike Auty
90ef8f363f
Have hivelist traverse in both directions in case of invalid addresses.
2019-04-11 00:38:46 +01:00
Mike Auty
5b8645bd1f
Revert IntFlag change until we drop python 3.5 support.
2019-04-05 22:56:36 +01:00