Matt Tressler and ikelos
34ff856a79
Updated imports to reflect new location of utility class; plugins are no longer outputing anything so commiting for Andrew to take a look at
2020-07-30 23:24:23 +01:00
Matt Tressler and ikelos
355c25fefb
added parameter type to generate_kernel_handler_info
2020-07-30 23:24:23 +01:00
Matt Tressler and ikelos
ddec0d482d
added kernel string to linux constants file; changed automagic methods so that they reconstruct the kernel object within the method for consistancy with other methods
2020-07-30 23:24:23 +01:00
Matt Tressler and ikelos
b9f5450ac3
added docs to automagic methods, fixed missing return types, changed parameters to be more specific
2020-07-30 23:24:23 +01:00
mtressler and ikelos
d61034bca8
Removed unnecessary code from tty_check.py
2020-07-30 23:24:23 +01:00
Matt Tressler and ikelos
314b6aa2c6
added some documentation
2020-07-30 23:24:23 +01:00
Matt Tressler and ikelos
44911bf54a
Fixed tty_check not finding the ttyhook module
2020-07-30 23:24:23 +01:00
Matt Tressler and ikelos
512cc8b451
fixed some formatting for tty_check.py
2020-07-30 23:24:23 +01:00
Matt Tressler and ikelos
ec8e9161bf
created tty_check.py; edited automagic/linux.py to add kernel tracking abilities
2020-07-30 23:24:23 +01:00
Mike Auty
03877ef2ec
Core: Maintain 3.5.3 compatibility
2020-07-30 22:27:26 +01:00
Mike Auty
b04fd7c9bd
Objects: Update enumeration method to is_valid_choice
2020-07-29 20:25:34 +01:00
Mike Auty
180eee569f
Objects: Add a convenience function for validating enum values
2020-07-29 20:25:34 +01:00
Mike Auty
bbaf4f22d6
Plugins: Remove unnecessary dependency for yarascan
2020-07-29 20:18:03 +01:00
Mike Auty
a5ecae29cc
Configuration: Improve the VersionableInterface documentation
2020-07-29 20:18:03 +01:00
Mike Auty
3eb463475b
Core: Refactor versioning and associated requirements
2020-07-29 20:18:03 +01:00
Mike Auty
2c39489790
Yarascan: Move most of yarascanning into a versionable plugin
...
This refactors common yara tasks, so we can use the plugin versioning to
keep track of changes to the YaraScanner class.
2020-07-29 20:18:03 +01:00
Mike Auty
faaa3bf6d8
Caching: Only cache remote files
2020-07-28 21:03:16 +01:00
Mike Auty
123e9bc8a3
Registry: Fix error message
2020-07-28 20:49:53 +01:00
Mike Auty
54b62709d1
Hashdump: Reformat and convert to proper byte handling
2020-07-28 20:49:27 +01:00
Andrew Case
dec13f5082
Linux - stash the Linux kernel virtual address
2020-07-28 13:16:40 -05:00
Jack Wenger and ikelos
465a7ca6ad
Added documentation and logging
2020-07-28 17:59:57 +01:00
Jack Wenger and ikelos
72bc40ee69
added hashdump
2020-07-28 17:59:57 +01:00
Andrew Case and ikelos
75d4390255
Remove extra debug prints
2020-07-28 17:00:20 +01:00
Mike Auty
8481406488
Linux: Support stashing the KASLR
2020-07-28 17:00:20 +01:00
Mike Auty
a4b50d183d
Mac: Stash the verified ASLR shift and improve logging
2020-07-28 17:00:20 +01:00
Andrew Case and ikelos
f6a1b28424
First attempt and better DTB and ASLR validation. Debugging statements left in.
2020-07-28 17:00:20 +01:00
Mike Auty
13e36ec58a
Core: Rerun yapf across the codebase.
2020-07-28 16:57:48 +01:00
Mike Auty
cbd40db053
Linux: Restore accidentally dropped kobject definition
2020-07-28 16:53:24 +01:00
xabiugarte and Mike Auty
fedd9c5519
Fixes on coding style
2020-07-28 16:46:43 +01:00
xabiugarte and Mike Auty
01dea6f3a8
Add elf parsing and symbol retrieval for linux kernel modules
2020-07-28 16:46:40 +01:00
Mike Auty
a980374eb8
Automagic: Fix issue in recent refactor
2020-07-28 11:15:16 +01:00
Mike Auty
61563350b3
Linux/Mac: Refactor *nix Utilities classes
2020-07-28 11:15:16 +01:00
Mike Auty
dc1e5064c9
Framework: Move cache_clear function to the framework
2020-07-26 22:57:33 +01:00
Mike Auty
8e6e966fb9
Requirements: Attempt to fix issue with python3.5
2020-07-23 02:23:31 +01:00
Mike Auty
667329e2fd
Mac: Fix pslist pid_filter function
2020-07-23 02:02:01 +01:00
Mike Auty
9295f41586
Plugins: Convert existing plugins over to use a list for PIDs
2020-07-23 02:02:01 +01:00
Mike Auty
31600254b9
Codebase: Apply yapf across the codebase.
2020-07-23 01:31:41 +01:00
mtressler and ikelos
79cf041283
Update check_modules.py
...
Removed unnecessary header info. A symbol table without the module_kset struct will now raise a TypeError
2020-07-21 23:00:52 +01:00
Matt Tressler and ikelos
4092bdb5de
changed from windows to linux line endings
2020-07-21 23:00:52 +01:00
Matt Tressler and ikelos
82a6b23669
Completed linux_check_modules. Added kobject extension as needed for check_module plugin
2020-07-21 23:00:52 +01:00
Andrew Case and ikelos
ef97c672e3
Check for invalid vnode pointers before processing path
2020-07-18 17:06:50 +01:00
Mike Auty
a173f12fce
Plugins: Normalize InvalidAddress exception handling
2020-07-18 16:38:49 +01:00
Mike Auty
43ae291815
Plugins: Add back in the checks because the filter might trip them
2020-07-18 16:38:49 +01:00
Mike Auty
73ad2bcd4e
Plugins: Since procs have been instantiated, checks aren't needed
2020-07-18 16:38:49 +01:00
Mike Auty
d15b23aa19
Plugins: Fix pslist_method inconsistencies
2020-07-18 16:38:49 +01:00
Mike Auty
7673dd8d2d
Mac: Consolidate methods of listing processes
...
This also updates all other plugins that rely on process listing
and theoretically allows them to choose their preferred method of
process listing. At the moment, the default (first in the method list)
is chosen. An optional pslist_method StringRequirement can be added to
each plugin, but using the list in the requirements could break if the
pslist plugin is too old (ie, using the list would happen before the
PluginRequirement gets checked).
If this is a feature we want, it should be easy to add to all but
netstat, which does not parameterize the list of processes.
2020-07-18 16:38:49 +01:00
Andrew Case and ikelos
0ccb1f82e6
Change copyright year and plugin doc strings
2020-07-18 16:38:49 +01:00
Andrew Case and ikelos
4799e8551e
Add process listing through examination of the process group hash table
2020-07-18 16:38:49 +01:00
Mike Auty
fb467332c6
Plugins: Yapf reformat linux check_creds plugin
2020-07-18 15:36:30 +01:00
mtressler and ikelos
8f1b338996
Update check_creds.py
...
changed behavior of plugin with it is run with a bad symbol table. Instead of a vollog.error, a TypeError exception is raised with information as to why it was raised.
Also removed unnecessary header info.
2020-07-18 15:29:30 +01:00