Mike Auty
0ecf68af0f
Support table remapping for referenced symbol names.
2017-11-27 14:39:46 +00:00
Mike Auty
60e1aebaf8
Improve the plugin help descriptions.
2017-11-25 16:19:47 +00:00
Mike Auty
0ad6294662
Reuse the cache if we're within the same ResourceAccessor.
...
This effectively means that the FileTranslationLayer will reuse the
cached file even with multiple opens, but rerunning python, or starting
a new context (with a new FileTranslationLayer but on the same URL) will
cause a redownload whether necessary or not. This ensures that running
volatility as an engine (inside a long lived python session) will not
prevent a file being checked again later.
Other caching mechanisms (such as last-modified) should be used to
determine if the cached file is still valid.
Note this may cause issues if plugins run concurrently.
2017-11-25 14:00:16 +00:00
Mike Auty
7a40d8128c
Add in support for the smb protocol when loading files.
2017-11-24 22:28:14 +00:00
Mike Auty
917829d87f
Reduce the number of times a ResourceAccessor is created, and use all handlers.
2017-11-24 22:27:36 +00:00
Mike Auty
30059766b6
Plug the WindowsMixin into the automagic.
2017-11-24 12:02:34 +00:00
Mike Auty
e43ca15630
Improve the logging for scan failures.
2017-11-24 00:39:28 +00:00
Mike Auty
2d570fdb62
Fix up the broken get_symbols_by_location call.
2017-11-23 01:36:16 +00:00
Mike Auty
2322a1b071
Pass the keypath through the recursion rather than expensively regenerating it.
2017-11-23 01:02:06 +00:00
ikelos and GitHub
678ad2c72c
Merge pull request #12 from superponible/master
...
change name of ntsymbols and call to get_key
2017-11-22 23:02:01 +00:00
Dave Lassalle
fdcab2760e
change name of ntsymbols and call to get_key
2017-11-22 16:03:55 -06:00
Mike Auty
51f508e602
Allow for substring matching on plugin names.
2017-11-14 11:04:47 +00:00
Mike Auty
b075d8c31c
Standardize on nt_symbols for standard symboltable requirements.
...
It's longer to type, but people shouldn't be typing it directly.
They should be pulling the value from the config and using that, which
can default to 'nt' if necessary.
2017-11-13 01:27:22 +00:00
Mike Auty
330832e546
Just to make it easier in case of renames, etc.
2017-11-13 01:20:08 +00:00
Mike Auty
327c8cb073
Make use of the hivelist plugin when no offset is provided to printkey.
2017-11-13 01:19:54 +00:00
Mike Auty
a60fcba32f
Make sure we don't assume that the primary layer's config lives under our own.
2017-11-13 01:18:54 +00:00
Mike Auty
769e1226c4
Make creating subconfigs simpler from configurables.
2017-11-13 00:59:01 +00:00
Mike Auty
9af49a49a9
Code improvement not to re-lookup the size of an unsigned int every turn of a loop.
2017-11-11 22:35:40 +00:00
Mike Auty
3a591688a6
Add in a little more information about signatures.
2017-11-11 15:34:06 +00:00
Mike Auty
35d47b0fb0
Improve checks for invalid values
...
We determine address_masks using log/ln2, which cannot accept 0.
Therefore we don't support address spaces with a maximum_address of 0.
This can affect registry hives, so we've added a check in registry hives
to prevent creating layers with invalid maximum_addresses.
2017-11-11 15:15:14 +00:00
Mike Auty
18f1e5ae90
Re-order the output of the printkey plugin.
2017-11-10 18:08:06 +00:00
Mike Auty
f58cdf73f1
Remove debugging print and use get_node rather than recasting.
2017-11-09 23:20:53 +00:00
Mike Auty
eb76cab749
Add in Big Data support.
2017-11-09 23:16:58 +00:00
Mike Auty
be1ebf03b0
Don't forget the constants import.
2017-11-09 23:16:46 +00:00
Mike Auty
18b84e31a5
Don't forget the constants import.
2017-11-09 23:16:30 +00:00
Mike Auty
527ef44800
Make sure the cell boundaries are checked correctly.
2017-11-09 23:13:38 +00:00
Mike Auty
def6de51bd
Add in the ability to get a symbol table from a specific object (often self.get_symbol_table).
2017-11-09 23:11:05 +00:00
Mike Auty
479848fde7
Improve subkey traversal by catering for various _CM_KEY_INDEX structures.
2017-11-08 11:41:06 +00:00
Mike Auty
918452f067
Remove deprecated volatile property in favour of the helper-prefixed property namespace.
2017-11-08 11:40:45 +00:00
Mike Auty
497f0f4950
Registry node with RI signature are effectively _CM_KEY_INDEX, just with single item elements.
2017-11-08 11:40:17 +00:00
Mike Auty
2db214e2f8
Ensure we appropriately truncate unicode strings.
2017-11-08 01:00:53 +00:00
Mike Auty
7c6970212f
Fix recursion (it wasn't being passed the argument).
2017-11-08 01:00:15 +00:00
Mike Auty
ba9ed5e3eb
Add minor comments about the jar uri scheme.
2017-11-08 00:13:26 +00:00
Mike Auty
f3f68e34cf
Change exception output to not have so many spaces.
2017-11-06 10:35:08 +00:00
Mike Auty
bbae34f1d5
Attempt to resolve issues with <python-3.6 json module not loading bytes.
2017-11-06 10:09:44 +00:00
Mike Auty
adfc1f889a
Add a comment about caching files that have been unzipped.
2017-11-06 00:48:33 +00:00
Mike Auty
3a215c185e
Ensure the linux caching happens early, so the user doesn't have to run it twice.
2017-11-06 00:17:30 +00:00
Mike Auty
c0e2d7499a
Ensure that magic isn't a hard dependency.
...
We rely on file extensions, but if we throw an Exception on a bad file
extension then it's not really our fault.
2017-11-05 22:46:24 +00:00
Mike Auty
71d938d78b
Add in support for looking for symbols in zip files.
...
We use the jar scheme because that's actually registered with the right
bodies, even if the syntax is a bit weird. The contents is still
processed by the ResourceAccessor meaning it can be compressed with any
of the supported compression methods.
2017-11-05 22:29:46 +00:00
Mike Auty
a21d0c174a
Fix the magic detection and add logging to the ResourceAccessor.
2017-11-05 22:29:37 +00:00
Mike Auty
b6d932f4a5
Refactor the ResourceAccessor because it isn't an interface.
...
It's not strictly limited to layers either, but I don't really want to
create a whole extra generic file to put this in, so layers will do.
2017-11-05 21:27:56 +00:00
Mike Auty
f6ac9c8367
Remove a no longer used function, so it doesn't get stuck in the API forever.
2017-11-05 15:28:38 +00:00
Mike Auty
671f65ed56
Centralize the ISF locating code.
...
This might benefit from a recache of the linux banners, although it
should continue to work no recache is performed.
We're now in a position to add support for loading symbols directly from
zip files by altering the ResourceAccessor and adding code to the
symbol finder.
2017-11-05 15:18:20 +00:00
Mike Auty
fd582f62e2
Fix a potential exception when earlier automagics don't succeed.
2017-11-04 18:54:52 +00:00
Mike Auty
585ec3f72d
Change the way plugin failures are reported.
2017-11-04 18:54:23 +00:00
Mike Auty
9d7d547667
Minor linting.
2017-11-04 18:45:18 +00:00
Mike Auty
a4b4a8eed3
Improve the error handling with automagics.
2017-11-04 18:45:08 +00:00
Mike Auty
8166b0cc96
Add better logging around the stacker.
2017-11-04 17:13:01 +00:00
Mike Auty
d9d67efa3a
Add in the capability to stash linux_banners.
...
Since the stacker and Linux automagic will always be different objects
(even if they're the same class), and we don't want to add OS specific
code to the stacker, this is the simplest way of allowing the Linux
symbol automagic to get information from the dtb finding stacker.
2017-11-04 17:09:59 +00:00
Mike Auty
dab5caf104
Paths from the banner cache are already URIs, so we don't need to reconvert them.
2017-11-04 15:52:02 +00:00