Commit Graph
1778 Commits
Author SHA1 Message Date
Mike Auty 3d87b06c36 Add in documentation to all the constants. 2019-08-18 18:55:57 +01:00
Mike Auty 37e13321f9 Fix warnings when generated documentation. 2019-08-18 18:30:44 +01:00
Mike Auty a9f4495307 Improve the look of docs generated from CLI classes. 2019-08-18 18:30:25 +01:00
Mike Auty ea7ca23987 Update the documentation generation and sphinx used. 2019-08-18 18:28:34 +01:00
Mike Auty 95f38aaf5d Fix up whitespace errors. 2019-08-18 01:22:10 +01:00
Mike Auty c66f7ff3fd Add a little extra documentation and fix a typo. 2019-08-18 01:20:56 +01:00
Mike Auty cb57905585 Try out a different style of documentation and options. 2019-08-18 01:20:32 +01:00
Mike Auty 57510803d5 Fix up an issue when removing PoolHeaderSymbolTable. 2019-08-18 01:19:34 +01:00
Mike Auty 6000d6c322 Update documentation around the Intermediary Symbol Format. 2019-08-17 23:22:04 +01:00
Mike Auty 1082429aab Don't use a separate symbol table class just to add a class override. 2019-08-17 23:20:46 +01:00
Mike Auty 35d8faae83 Add in exception throwing if case of no valid response. 2019-08-15 22:09:41 +01:00
Mike Auty 433e40a606 Support some middling versions of windows 10 in virtmap. 2019-08-15 21:49:21 +01:00
Mike Auty 287c7ce0b0 Minor fixes for virtmap given the recent module refactoring. 2019-08-15 21:05:49 +01:00
Mike Auty 8ccf8b045d Add in first draft of virtmap plugin. 2019-08-14 20:53:45 +01:00
Mike Auty 3af89df1e7 Update the docstrings for the core Context methods. 2019-08-14 20:50:42 +01:00
Mike Auty 5db6ade2ea Change object_type parameter for object_from_symbol. 2019-08-14 20:50:42 +01:00
Mike Auty be27aab8ae Refactor symbol to object_type (so it doesn't shadow builtin type). 2019-08-14 20:50:42 +01:00
Mike Auty 18283ab410 Move to an object_from_symbol model
Note: creation of enumerations can be done using Context.object, which
should allow reference of enumeration members by normal type objects.

If it turns out enumerations are never referenced from types, we can
easily remove the try/except in the Module.object method.
2019-08-14 20:50:42 +01:00
Mike Auty 991b30e056 Typing fix-ups. 2019-08-14 20:50:42 +01:00
Mike Auty 65f561be31 Limit modules to only accepting strings not templates. 2019-08-14 20:50:42 +01:00
Mike Auty 5362e2094e Initial attempt at cleaning up the API
Context.object accepts a template or a string name (and now a type
flag).  Module.object only accepts a string (because a template already
has most of the stuff built in and might as well be passed to the
Context.object constructor).

The gotcha here is the absolute flag, which must now be set
appropriately in all cases *except* where the module is constructed
with an offset of 0 (whereby it will have no impact).
2019-08-14 20:50:42 +01:00
superponibleandikelos 95ac651f7e make get_maxaddr private and rename maxaddr variables for clarity 2019-08-13 20:37:46 +01:00
superponibleandikelos 0a5861350a use UnreadableValue 2019-08-13 20:37:46 +01:00
superponibleandikelos 3361d77d17 remove redundant log message 2019-08-13 20:37:46 +01:00
superponibleandikelos ef7e7fd905 only catch InvalidAddressException 2019-08-13 20:37:46 +01:00
superponibleandikelos 317c1cdb7b store cmhive name instead of _cmhive 2019-08-13 20:37:46 +01:00
Dave Lassalleandikelos 60193b2a3f remove HBIN bounds check 2019-08-13 20:37:46 +01:00
Dave Lassalleandikelos 0e22eea58d improved exception handling in registry and printkey 2019-08-13 20:37:46 +01:00
Mike Auty 8e4fd03190 Improve the help for the renderer global CLI option. 2019-08-12 00:35:17 +01:00
Mike Auty fb68e22767 Expose the context for a module, so we don't have to ship both around. 2019-08-12 00:17:09 +01:00
Mike Auty 39fa9057ff Remove errant scan_kernel from svcscan for rekall. 2019-08-11 23:32:34 +01:00
Mike Auty bbac649a62 Remove the dependency on pdbparse since pdbparse-to-json is no longer necessary. 2019-08-11 17:39:34 +01:00
Mike Auty 75f386784a Clean up development directory. 2019-08-11 17:33:53 +01:00
Mike Auty 0b71c1130f Add in the image-hash to make results easier to match up. 2019-08-11 17:19:59 +01:00
Mike Auty 196da74fdb Fix up a manual typo (and remove trailing spaces). 2019-08-11 17:16:57 +01:00
Mike Auty 40d04ed1ff Improve comparison titles, store stderr and output up until timeout. 2019-08-11 11:33:42 +01:00
Mike Auty cdc19ad5fa Add in 5 minute timeout for comparison tests. 2019-08-10 18:58:47 +01:00
Mike Auty 4cde0da8a9 Support passing through functions from specific to generic template. 2019-08-10 00:25:21 +01:00
Mike Auty b2da35c05a Revert "Apply relative offsets to type_name as well as symbol_names for modules."
This reverts commit d67fcc9a6a.
2019-08-10 00:23:18 +01:00
Mike Auty d67fcc9a6a Apply relative offsets to type_name as well as symbol_names for modules. 2019-08-09 20:08:05 +01:00
Mike Auty 8ddfe8ce16 Update plugins using the old PESymbolTable method 2019-08-09 00:49:05 +01:00
Mike Auty 6f7dc1a75e Add in the scan_kernel parameter for rekall to offer a fair comparison. 2019-08-08 23:20:59 +01:00
Mike Auty a412d3ef2f Guard against list size returns. 2019-08-08 20:30:33 +01:00
Mike Auty 1120854350 Ensure we descend LF_MODIFIERs when finding forward referenced array sizes. 2019-08-08 17:15:25 +01:00
Mike Auty fbeab3608c Make we raise if the _POOL_HEADER type doesn't exist. 2019-08-08 01:09:56 +01:00
Mike Auty 253ce69fc9 Refactor poolscanner layer to move more into the parallel scanner. 2019-08-07 18:37:56 +01:00
Mike Auty 9ed1a5a5b6 The header is not dependent on the constraint, so only construct it once. 2019-08-07 16:33:13 +01:00
Mike Auty e3057e305d Support parallelism on CLI. 2019-08-07 11:44:29 +01:00
Mike Auty 6c23968a11 Add in support for choosing specific frameworks to test. 2019-08-06 13:32:03 +01:00
Mike Auty f8587a08f2 Refactor and add support for testing rekall. 2019-08-05 01:20:24 +01:00