Commit Graph
5288 Commits
Author SHA1 Message Date
j-t-1andGitHub 39cb75acca Slightly modify documentation
Include regex_scan, new functionality of volshell.
2024-12-10 17:02:48 +00:00
j-t-1andGitHub 0b2f4fdeb7 Remove redundant part of if statement
Also reorder imports.
2024-12-10 12:26:39 +00:00
j-t-1andGitHub faa6cab797 Remove redundant part of if statement
Also reorder imports.
2024-12-10 12:16:42 +00:00
j-t-1andGitHub 4bccf11629 Remove redundant part of if statement
Also reorder imports.
2024-12-10 11:31:16 +00:00
j-t-1andGitHub fdd49d0921 Slightly modify documentation 2024-12-10 10:11:26 +00:00
j-t-1andGitHub 1cde9ae06e Slightly modify volshell.rst 2024-12-10 09:46:28 +00:00
David McDonald a07ee5a0d5 fix(Windows: Handles): Unreliable SAR value on 24H2
Handles are not being decoded in 24H2+ samples. This is because the
`Handles._decode_pointer` method grabs the SAR shift value from the
disassemble function, but in these samples this value (`0x11`) is
incorrect. Adding a fallback to the default SAR value of `0x10` if the
obtained pointer is not valid in the kernel address space  resolves the
issue.
2024-12-09 18:11:27 -06:00
ikelosandGitHub b8298a345f Merge pull request #1169 from volatilityfoundation/mftscan_updates_resident_data_plugin
Add new resident data displaying plugin. Scan in correct layer. Condense code and remove duplication. Fix bugs
2024-12-09 20:24:27 +00:00
Andrew Case 13eae6c3df Add capstone to test system requirements. Allow lazy type checks 2024-12-09 13:19:06 -06:00
Andrew Case af65d7e32d Address feedback 2024-12-09 13:10:34 -06:00
Andrew Case e7fca5a83f Update year 2024-12-09 13:10:34 -06:00
Andrew Case 262c7f1aa7 Make VAD API public as intended 2024-12-09 13:10:34 -06:00
Andrew Case fce2125a8e Make VAD API public as intended 2024-12-09 13:10:34 -06:00
Andrew Case 9f8e39efa0 Fix formatting problem between black versions 2024-12-09 13:10:34 -06:00
Andrew Case e66a3e929b Add detection of direct and indirect system calls 2024-12-09 13:10:34 -06:00
ikelosandGitHub ec550232ac Merge pull request #1388 from eve-mem/issue_1387
Interfaces: change allow list for filenames to ensure they work safely on windows. Fixes issue #1387
2024-12-09 18:58:40 +00:00
Andrew Case 582feccf93 Address feedback 2024-12-09 12:56:07 -06:00
eve b86e839718 Interfaces: change allow list for filenames to ensure they work safely on windows. Fixes issue #1387 2024-12-09 18:30:19 +00:00
ikelosandGitHub 2ae723513a Merge pull request #1386 from j-t-1/doc
Cosmetic changes to documentation
2024-12-07 17:19:38 +00:00
j-t-1andGitHub 45f9064623 Cosmetic changes to documentation 2024-12-07 17:11:49 +00:00
j-t-1andGitHub e165c78ba7 Cosmetic changes to documentation 2024-12-07 16:37:39 +00:00
j-t-1andGitHub 04d2554442 Cosmetic changes to documentation 2024-12-07 16:36:18 +00:00
j-t-1andGitHub 97698cc5ed Cosmetic changes to documentation 2024-12-07 16:29:58 +00:00
j-t-1andGitHub 9ebc0bd90d Cosmetic changes to documentation 2024-12-07 16:20:45 +00:00
Mike Auty d29c23e922 Windows: Protect against missing _MM_SESSION_SPACE symbol 2024-12-07 15:52:58 +00:00
ikelosandGitHub 78e3ee26a0 Merge pull request #1384 from j-t-1/doc
Small documentation changes
2024-12-07 01:04:22 +00:00
j-t-1andGitHub 93a47e811b Small documentation changes 2024-12-06 21:52:51 +00:00
j-t-1andGitHub 846403115a Small documention changes 2024-12-06 16:00:03 +00:00
ikelosandGitHub e2cdbdc2bf Merge pull request #1382 from j-t-1/PYO
PEP 488 – Elimination of PYO files
2024-12-06 00:26:21 +00:00
j-t-1andGitHub f11ef06c27 PEP 488 – Elimination of PYO files
Python 3.5 implememted PEP 488, eliminating .pyo files.
2024-12-05 21:30:20 +00:00
j-t-1andGitHub 5acf8858d9 PEP 488 – Elimination of PYO files
Python 3.5 implememted PEP 488, eliminating .pyo files.
2024-12-05 18:31:04 +00:00
Mike Auty 3ff304ceed Layers: Fix intel bug introduced in commit 73d4f2f
The patch failed to mask the incoming address to the maximum physical
address.  This allowed non-canonical addresses (potentially within the
page table) to be looked up incorrectly.

Fixes #1374.

Thanks to @the-rectifier for quickly identifying the issue!
2024-12-03 19:58:23 +00:00
Abyss Watcher 20f15d3591 modular physical_layer access 2024-12-02 11:34:49 +01:00
ikelosandGitHub e4c552050c Merge pull request #1377 from gcmoreira/pytest_image_autoselection_improvement
Testing: Enable automatic OS image selection by matching test name and image filename prefixes
2024-12-01 11:06:46 +00:00
ikelosandGitHub fbc72d35b9 Merge pull request #1368 from gcmoreira/linux_pslist_dependencies_fix_1366
Linux pslist dependencies fix 1366
2024-12-01 11:00:12 +00:00
ikelosandGitHub 4d628c839b Merge pull request #1376 from gcmoreira/fix_pretty_renderer_hex_bytes_as_text
Renderers - Fix HexBytes formatter for pretty renderer
2024-12-01 10:52:00 +00:00
Gustavo Moreira 535ce3a22a testing: Enable automatic selection of the OS image based on the test and filename prefix, addressing an issue in the development environment.
For example, when using VSCode with pytest, test autodiscovery triggers pytest_generate_tests(), adding all images to each test case. This causes issues, as Linux tests end up being executed with Windows and Mac images, and vice versa.
2024-12-01 19:34:35 +11:00
Gustavo Moreira c19a54cbd9 testcases: Minor cleanup: Renaming and reordering functions to align with the Linux/Windows test cases 2024-12-01 14:08:53 +11:00
Gustavo Moreira 7ae27c4eaa Merge branch 'develop' into linux_pslist_dependencies_fix_1366 2024-12-01 13:24:53 +11:00
Gustavo Moreira 3c20e46902 renderers: Fix HexBytes formatter to apply padding also at the end of the string, ensuring proper output alignment when the pretty renderer justifies each line to the right 2024-12-01 12:36:35 +11:00
ikelosandGitHub 9222f4915a Merge pull request #1371 from volatilityfoundation/issues/use-yara-scanner-over-handling-yara-directly
Fix up vmayarascan and vadyarascan to use yarascan properly
2024-12-01 01:26:04 +00:00
Mike Auty d404747de5 Tests: Add in vadyarascan tests 2024-12-01 00:04:46 +00:00
Mike Auty 2dc1686289 Windows: Protect the SERICE_RECORD is_valid function a little more
The request to .Order could fail depending on where the structure lies
in memory.
2024-11-30 13:36:17 +00:00
Mike Auty 56f6ef0add Include a test developed by @gcmoreira and @eve-mem 2024-11-30 11:52:16 +00:00
Mike Auty 3df385369c Ensure the VAD/VMA gets scanned in a single block 2024-11-30 11:28:09 +00:00
ikelosandGitHub ba98b088cb Merge pull request #1369 from gcmoreira/logging_producer_information
Linux/Mac: Log producer metadata information
2024-11-29 10:27:32 +00:00
Mike Auty 393db1050f Windows: protect again mz_offsets being None 2024-11-29 08:51:06 +00:00
Mike Auty 0030129ff8 Make suggested fixes to reduce loops and ignore insane sections 2024-11-29 08:43:04 +00:00
Gustavo Moreira 77778ee6f6 Linux/Mac: ISF metadata: Rename s/DWARF/POSIX/, as I'm not happy with the generic name. BTF source could potentially generate the same keys 2024-11-29 19:35:18 +11:00
Gustavo Moreira b8023f0c97 Linux/Mac: Address code review suggestions
- Add getters for Linux/Mac ISF sources
- Avoid using internal attributes
- Use the dict repr instead of walking the dict to simplify code
2024-11-29 19:05:27 +11:00