Commit Graph
164 Commits
Author SHA1 Message Date
Mike Auty 10cf65fb60 Add in better documentation for callbacks. 2019-09-10 00:43:44 +01:00
Michael Lighandikelos 4e3db7a3de add PluginRequirements for ssdt and svcscan. add missing _version to svcscan 2019-09-08 16:08:48 +01:00
Michael Lighandikelos 1d7f2a9582 use ntkrnlmp.object() instead of context.object(). remove config_path argument to list* functions 2019-09-08 16:08:48 +01:00
Michael Lighandikelos 50548bac73 reformat with yapf 2019-09-08 16:08:48 +01:00
Michael Lighandikelos e71b72b3a7 add the windows callbacks plugin 2019-09-08 16:08:48 +01:00
Mike Auty 421af88c29 Classmethod make_subconfig so other classmethods can use it. 2019-09-08 14:50:48 +01:00
Mike Auty 03bc3d927d Improve the name of a handles exposed function. 2019-09-08 13:22:42 +01:00
Mike Auty 3318e9c4a5 Fix a typo introduced in 5362e2094e. 2019-09-08 01:58:46 +01:00
Mike Auty 189b8c4d69 Update the windows info plugin with classmethods. 2019-09-07 23:00:41 +01:00
Mike Auty e922cef316 Improve docstrings for all plugins, and reformat all docstrings. 2019-09-07 22:59:54 +01:00
Mike Auty dc0a809729 Printkey: Don't offer two options for the same value. 2019-09-07 22:05:09 +01:00
Mike Auty 959e1617fd Shift one-time checks out of loops. 2019-09-07 12:40:32 +01:00
Mike Auty b158c58310 Ensure non-found keys mimic found key output a little closer. 2019-09-01 22:44:42 +01:00
Mike Auty 952a1b9d69 Move printkey recursion around to get proper tree depth. 2019-09-01 16:17:26 +01:00
Mike Auty f040ceed96 Ensure keys and values are at the same level. 2019-09-01 16:10:58 +01:00
Mike Auty 3d7b2a520b Ensure the tree output for printkey doesn't jump into deep layers. 2019-09-01 16:05:51 +01:00
Mike Auty c2feba6651 Remove debugging calls from layerwriter plugin. 2019-09-01 15:50:29 +01:00
Mike Auty 39c4d061a1 Convert registry.printkey hive_walker to a class method. 2019-08-31 14:32:35 +01:00
Mike Auty a3caf39097 Use a mapping to determine kind to class. 2019-08-31 12:57:53 +01:00
Mike Auty 35dbdfc69d Add in PluginRequirement for proc_maps plugin. 2019-08-27 23:35:19 +01:00
Mike Auty a9853eca50 Fix the copyright headers (and yapf) in the mac plugins. 2019-08-27 23:34:06 +01:00
Andrew Caseandikelos 6b4c13089d add mac_proc_maps 2019-08-27 23:31:01 +01:00
Andrew Caseandikelos 07ece011a3 Add mac_tasks 2019-08-27 23:28:51 +01:00
Mike Auty 9cde94bceb Change the license blurb on all files. 2019-08-27 23:11:00 +01:00
Mike Auty 42b2fb120a Swap TranslationLayerInterface decendents over to LinearMappedLayers 2019-08-27 21:09:13 +01:00
Mike Auty 71bb54379b Refactor the plugin versioning to be simpler to define. 2019-08-27 21:08:29 +01:00
Mike Auty 47c349e240 Add plugin requirements for all plugins. 2019-08-27 21:08:29 +01:00
Mike Auty 58dffe8795 Fix typos from the rebase, and add documentation. 2019-08-27 21:08:29 +01:00
Mike Auty a58f064ea8 Rework how the plugin_version is checked. 2019-08-27 21:08:29 +01:00
Mike Auty 11fc8654e3 Initial attempt at plugin versioning.
So this allows people to alter the APIs for their plugins and allows
plugins to verify the API is compatible with the one they expect.

It adds a version property to Plugin classes, and has a SemVer checking
method which can be called from other plugins to verify a plugin against
a particular version.
2019-08-27 21:08:29 +01:00
Mike Auty 6fc12e9b01 Make sure options are specific to each plugin.
So this feels like a contentious decision.  It'd be awesome to have the
options for the methods stored along-side the methods themselves.

The downside with this is that the thing accessing the configuration
data is always the plugin, so it's the plugin that must have requested
the configuration option.  This is also important in case the
description of the configuration option needs modifying for clarity or
providing context for how it will be used.

If the interface changes, all plugins calling the plugin methods will
need updating, so the config options can be updated if necessary.
2019-08-23 21:41:50 +01:00
Mike Auty d0b0a96ac1 Refactor the run_plugin method to more accurate construct_plugin. 2019-08-20 00:13:00 +01:00
Mike Auty c0f650ba78 Ensure Mac plugins are documented and add complex tasks documentation. 2019-08-18 22:35:34 +01:00
Mike Auty 37e13321f9 Fix warnings when generated documentation. 2019-08-18 18:30:44 +01:00
Mike Auty 57510803d5 Fix up an issue when removing PoolHeaderSymbolTable. 2019-08-18 01:19:34 +01:00
Mike Auty 1082429aab Don't use a separate symbol table class just to add a class override. 2019-08-17 23:20:46 +01:00
Mike Auty 35d8faae83 Add in exception throwing if case of no valid response. 2019-08-15 22:09:41 +01:00
Mike Auty 433e40a606 Support some middling versions of windows 10 in virtmap. 2019-08-15 21:49:21 +01:00
Mike Auty 287c7ce0b0 Minor fixes for virtmap given the recent module refactoring. 2019-08-15 21:05:49 +01:00
Mike Auty 8ccf8b045d Add in first draft of virtmap plugin. 2019-08-14 20:53:45 +01:00
Mike Auty 5db6ade2ea Change object_type parameter for object_from_symbol. 2019-08-14 20:50:42 +01:00
Mike Auty be27aab8ae Refactor symbol to object_type (so it doesn't shadow builtin type). 2019-08-14 20:50:42 +01:00
Mike Auty 18283ab410 Move to an object_from_symbol model
Note: creation of enumerations can be done using Context.object, which
should allow reference of enumeration members by normal type objects.

If it turns out enumerations are never referenced from types, we can
easily remove the try/except in the Module.object method.
2019-08-14 20:50:42 +01:00
Mike Auty 5362e2094e Initial attempt at cleaning up the API
Context.object accepts a template or a string name (and now a type
flag).  Module.object only accepts a string (because a template already
has most of the stuff built in and might as well be passed to the
Context.object constructor).

The gotcha here is the absolute flag, which must now be set
appropriately in all cases *except* where the module is constructed
with an offset of 0 (whereby it will have no impact).
2019-08-14 20:50:42 +01:00
superponibleandikelos 0a5861350a use UnreadableValue 2019-08-13 20:37:46 +01:00
superponibleandikelos 3361d77d17 remove redundant log message 2019-08-13 20:37:46 +01:00
superponibleandikelos ef7e7fd905 only catch InvalidAddressException 2019-08-13 20:37:46 +01:00
Dave Lassalleandikelos 0e22eea58d improved exception handling in registry and printkey 2019-08-13 20:37:46 +01:00
Mike Auty 8ddfe8ce16 Update plugins using the old PESymbolTable method 2019-08-09 00:49:05 +01:00
Mike Auty fbeab3608c Make we raise if the _POOL_HEADER type doesn't exist. 2019-08-08 01:09:56 +01:00