Commit Graph
2344 Commits
Author SHA1 Message Date
Mike Auty 288a017178 CLI: fix up the previous broken commit 2020-08-22 11:55:23 +01:00
Mike Auty fc5b051692 CLI: Apply the same specific config parsing to automagic 2020-08-22 11:18:01 +01:00
Mike Auty 91b0774a65 CLI: Only attempt to parse relevant config options
Fixes: #310
2020-08-22 11:08:48 +01:00
Mike Auty 3127c7a220 Intermed: Make extensions a reusable constant 2020-08-21 21:24:59 +01:00
Mike Auty 73f3c217bd Mac/Linux: Remove unnecessary imports 2020-08-18 09:15:13 +01:00
Mike Auty 90d347714c Mac: Correct patch ordering 2020-08-18 09:10:16 +01:00
Mike Auty 9b57d7a58c Plugins: Version Mac/LinuxUtilities classes 2020-08-18 09:07:32 +01:00
Mike Auty 75719c8393 Pdbconv: Improve typing without recording unnamed types 2020-08-17 23:09:13 +01:00
Mike Auty bd591bd5d8 Pdbconv: Revert typing correction that causes breakages 2020-08-17 17:10:47 +01:00
gcmoreiraandikelos 748dceefb7 Fix #291. It supports any level of depth of nested anonymous types. 2020-08-17 17:01:28 +01:00
Mike Auty 8e420cbe62 Core: Multiple typing fixes across the tree 2020-08-16 22:22:24 +01:00
AsafEitaniandikelos 377b8842b9 Update strings.py 2020-08-16 17:51:13 +01:00
AsafEitaniandikelos cbe31999b1 Update strings.py 2020-08-16 17:51:13 +01:00
Mike Auty 523156670d Documentation: Clarify the mapping output parameters 2020-08-16 00:50:17 +01:00
Andrew Caseandikelos 5734562997 Add mac.mount plugin 2020-08-14 22:43:52 +01:00
Mike Auty 15da1f5253 Plugins: Update pidlist_pid_hash_table to a pslist method 2020-08-14 22:39:40 +01:00
Andrew Caseandikelos b976a57920 add pslist_pid_hash_table 2020-08-14 22:39:40 +01:00
Mike Auty 833cfc5607 Plugins: Update the docstring for pslist_sessions code 2020-08-14 22:30:34 +01:00
Mike Auty 08b8564802 Plugins: Update pslist_sessions to be a different process lister 2020-08-14 22:30:34 +01:00
Andrew Caseandikelos 93e16a7151 add pslist_sessions plugin 2020-08-14 22:30:34 +01:00
Mike Auty 595a94304d Strings: Small bugfix as pointed out by AsafEitani 2020-08-13 10:32:56 +01:00
Mike Auty 51f48f7e93 Configuration: Fix inverted versioning logic 2020-08-13 00:08:33 +01:00
Mike Auty f3fd67abb2 Plugins: Update the recent plugins copyright date. 2020-08-12 22:37:47 +01:00
Mike Auty 3726e9e509 Setup.py: Add in option requirement of pycryptodome 2020-08-12 22:12:08 +01:00
Mike Auty 289afd504b Plugins: Minor clarifications and cleanups 2020-08-12 21:00:24 +01:00
Steffi Keeneandikelos 76d6764e81 cleanups 2020-08-12 20:56:15 +01:00
Steffi Keeneandikelos 5166bcbe95 Memdump and memmap running/tested with grrcon-0a7030d.imh 2020-08-12 20:56:15 +01:00
Steffi Keeneandikelos 2e765c7d70 working with grrcon- 2020-08-12 20:56:15 +01:00
Steffi Keeneandikelos 1c58043004 memdump running but not tested 2020-08-12 20:56:15 +01:00
Steffi Keeneandikelos 1472048b41 testing memmap 2020-08-12 20:56:15 +01:00
Mike Auty c1f6c224d7 Symbols: Resolve symbols returned from symbol_space.get_symbol
This ensures that ReferenceTemplates are not returned from a call to
symbol_space.get_symbol.  This is in keeping with the get_type method.

The symbol_space containing all symbol tables has visibility of all
tables and can cross-resolve amongst them.  Asking a specific table
for a type may result in a ReferenceTemplate.  This feels like a
better solution than having individual tables ask their parent space
to fill in the details of sibling tables.

Fixes #279.
2020-08-12 20:39:33 +01:00
AsafEitaniandikelos f7b456a703 Update strings.py 2020-08-12 14:57:57 +01:00
AsafEitaniandikelos 67c515f38d Improved strings efficiency
1. Replaced readlines() with readline() to prevent loading the entire strings file to memory all at once.
2. Added process callback to indicate the progression.
3. Converted the re.compile of strings parse_line to global in order to prevent compilation for each line.
4. Changed the regex to not include the trailing newline (\n)
2020-08-12 14:57:57 +01:00
Mike Auty 4c3bf7222e Documentation: Describe the various AbsentValues. 2020-08-10 23:04:18 +01:00
Mike Auty 49e778724b Documentation: Add in section about TreeGrid column types 2020-08-10 22:36:20 +01:00
Mike Auty 77101c5617 Documentation: Slight code fix in the library page 2020-08-10 22:22:25 +01:00
Mike Auty 03d69204f3 Documentation: Add in using volatility as a library 2020-08-10 22:17:40 +01:00
Mike Auty 99a536e57e CLI: Revert epilog changes 2020-08-07 00:15:19 +01:00
Matt Tresslerandikelos 2467e3986d added address mask to fix issue with kernel tracking 2020-08-06 18:12:42 +01:00
Matt Tresslerandikelos eb2d7715ce fixed poor variable name, removed unnecessary code 2020-08-06 18:12:42 +01:00
Matt Tresslerandikelos 8f7171ac5f fix copyright year 2020-08-06 18:12:42 +01:00
Matt Tresslerandikelos d7619d6170 created linux_check_idt; plugin currently is not finding the module names for each entry in idt table 2020-08-06 18:12:42 +01:00
Mike Auty a80400cfa6 CLI: Add additional help about 'vol.py plugin --help' 2020-08-06 16:59:53 +01:00
Mike Auty 0b392f5186 Windows: Add a version to the info plugin now its got classmethods 2020-08-05 11:47:04 +01:00
Mike Auty 2166834d87 Timeliner: Actually make use of the TextIoWrapper 2020-08-03 20:36:40 +01:00
Mike Auty cbea698ab0 Timeliner: Sort results and provide a filter
Sorts the results (as stated).  Note that user interfaces may decide to
sort their results in an order of their choosing.

Also added a parameter that can be provided multiple times to only allow
plugins that match (any of) the parameters provided.
2020-08-03 20:13:25 +01:00
Mike Auty fb1901ea89 Renderers: Fix the pretty renderer when no rows are emitted 2020-08-03 19:40:58 +01:00
Mike Auty a339fd0783 Linux: Fix keyboard_notifiers copyright year 2020-08-03 17:05:41 +01:00
Mike Auty 556c880c90 Codebase: Ensure all conversions to bytes handle unicode
All conversions using `latin-1` have been converted to
`raw_unicode_escape` which is like `latin-1`, but handles unicode
characters appropriately (with a `\u` prefix).

Since this is like `latin-1` it should have no impact on things that ran
previously, but those that would fail with a unicode error now will
present an encoded unicode string.  There may be situations where the
binary representation of unicode would be better (timeliner file
output?), but those can be changed when/if it's determined necessary.

Fixes #274.
2020-08-03 16:53:48 +01:00
Mike Auty ff32383f82 Yapf: Minor reformats for recent plugins 2020-08-03 16:33:10 +01:00