Commit Graph
5288 Commits
Author SHA1 Message Date
Mike Auty eb38756dbe CLI: Add deprecation warning to --write-config 2022-03-16 01:35:47 +00:00
Mike Auty fa723ec134 CLI: Implement specifying a config name to write 2022-03-16 01:29:20 +00:00
ikelosandGitHub 7d17c191e5 Merge pull request #675 from paulkermann/bugfix/is_vad_empty
Windows Malfind is_vad_empty error
2022-03-15 12:31:56 +00:00
Paul Kermann 7c89fc3f07 bug fix :( 2022-03-15 14:22:36 +02:00
ikelosandGitHub e1c157eb71 Merge pull request #673 from volatilityfoundation/feature/better-csv-support
Renderers: Use built-in python CSV support
2022-03-15 09:01:28 +00:00
Donghyun KimandGitHub 8aeaa83e6f Merge branch 'volatilityfoundation:develop' into feature/mbr-parser 2022-03-14 10:57:29 +09:00
Donghyun Kim f97348616f Define 'all_zero' default value, Update output column name 2022-03-14 09:47:34 +09:00
ikelosandGitHub 6c84568031 Merge pull request #660 from volatilityfoundation/feature/better-dtb-detection
Feature/better dtb detection
2022-03-13 22:05:31 +00:00
Mike Auty 0de8c645a4 Renderers: Add column headers for CSV 2022-03-13 21:20:04 +00:00
Mike Auty eba7ad1c0d Renderers: Use built-in python CSV support 2022-03-13 21:13:25 +00:00
Donghyun KimandGitHub 54a93a12f5 Merge branch 'volatilityfoundation:develop' into feature/mbr-parser 2022-03-11 12:49:04 +09:00
Donghyun Kim 4e4143223a Merge branch 'feature/mbr-parser' of https://github.com/Digitalisx/volatility3 into feature/mbr-parser 2022-03-10 13:52:07 +09:00
Donghyun Kim 1b71aad366 Update BootableFlag Symbol 2022-03-10 13:51:52 +09:00
Donghyun Kim a35fa04f00 Update BootableFlag Symbol 2022-03-10 01:12:49 +09:00
Donghyun Kim 7c00b2f4ea Add Code Comment, Hash Funtion, Exception 2022-03-10 00:13:46 +09:00
Donghyun Kim b6a14e6de4 Add Symbol code comment, hash 2022-03-09 23:42:21 +09:00
ikelosandGitHub 9aa0b5d6f7 Merge pull request #666 from volatilityfoundation/issues/issue631
Layers: Better checks on PAE page tables
2022-03-09 09:03:11 +00:00
Donghyun Kim 5de6462fae Restore mft.json 2022-03-09 17:09:36 +09:00
Donghyun Kim b01333115b __str__ Formatting 2022-03-09 17:08:27 +09:00
Donghyun Kim e0a512e9ff Add EOF of MBR Symbol 2022-03-09 16:13:25 +09:00
Donghyun Kim eda765d61d Update MBR Partition Entry Object Function 2022-03-09 16:12:32 +09:00
Donghyun Kim 7ff2572bec Merge branch 'feature/mbr-parser' of https://github.com/Digitalisx/volatility3 into feature/mbr-parser 2022-03-09 13:28:01 +09:00
Donghyun Kim acc3f6f352 Update Symbol Table, Load Physical Layer 2022-03-09 13:27:53 +09:00
Donghyun KimandGitHub 9eb93bb949 Merge branch 'volatilityfoundation:develop' into feature/mbr-parser 2022-03-09 08:50:26 +09:00
ikelosandGitHub b191626b0a Merge pull request #669 from Digitalisx/fix/typo-error
Fix Typo Error for some plugins, documents
2022-03-08 19:58:31 +00:00
Donghyun Kim 18770d0cd3 Fix glossary.rst Typo Error 2022-03-09 02:09:47 +09:00
Donghyun Kim 6c1fe42a37 Fix Docs, Framework, Windows Plugin Typo Error 2022-03-09 01:53:04 +09:00
Samuel Zurowski 4087236957 Changed named and used thread_group instead to ensure all threads are grabbed 2022-03-07 19:18:17 -05:00
Donghyun Kim 34a732a4f0 Fix Object Typo Error 2022-03-07 14:00:03 +09:00
Donghyun Kim a1023e51f5 Fix Renderes, Scanners, MFT Symbol Typo Error 2022-03-07 13:54:35 +09:00
Samuel Zurowski 68903c63df Added task_struct function to get each task_struct from the thread_nodes structure 2022-03-06 20:20:24 -05:00
Mike Auty 244751e9ae Layers: Better checks on PAE page tables
This checks that the very top level table points to the next four pages,
as we'd expected in general. This relies on the same assumptions as the
existing PAE detection did, ie that the PAE page_map maps the next four
pages immediately.

Previously we didn't check that the top page was valid, once we found
the self-referential pointer.  This adds in an appropriate check to
reduce false positives.

Closes #631.
2022-03-06 18:48:00 +00:00
Donghyun Kim 7570e82786 Configuration Yara Rules 2022-03-05 17:47:37 +09:00
Donghyun Kim 06961ce537 Initialize MBR Parser 2022-03-05 16:32:38 +09:00
Donghyun Kim 639f87a0a4 Remove Tab 2022-03-05 16:29:40 +09:00
Donghyun Kim f060562b27 Rebase 2022-03-05 16:29:09 +09:00
Donghyun Kim ad1ef807e7 Context Typo Error, MFT Symbol JSON Prettier 2022-03-05 16:27:07 +09:00
Donghyun KimandGitHub 6cb2b2bf84 Merge branch 'volatilityfoundation:develop' into develop 2022-03-05 15:43:38 +09:00
Mike Auty 670401eac7 Windows: Test unicode strings for length 0
In some tests we were checking whether asking for the string value threw
an InvalidAddressException through an error as to whether we should look
elsewhere for the data.  As of commit 265b2825 we now treat 0-length
strings as valid (as per #652), meaning we need to check for length 0
as well as invalid pointers.

If this crops up often, we may need to revisit the decision to make sure
its in keeping with how windows treats zero length strings, but for now
we only did it once for registry keys.

Closes #665
2022-03-03 20:35:39 +00:00
Donghyun Kim 49308eb18d Restore PR 2022-03-03 02:03:31 +09:00
Donghyun Kim dae8860577 Restore PR 2022-03-03 02:02:43 +09:00
Donghyun Kim 58782fcfe1 Typo Error Fix - Context module object Args code comment 2022-03-03 02:00:32 +09:00
Donghyun Kim 9868aeb906 Add Error Raise point 2022-02-28 14:12:25 +09:00
Donghyun Kim f156d237a4 Add 'ImportError' handling of the capstone module on malfind plugin. 2022-02-28 13:36:54 +09:00
ikelosandGitHub 9f8f6b2899 Merge pull request #658 from volatilityfoundation/feature/workaround-python-46654
Layers: Fix opening UNC paths on windows
2022-02-26 13:26:48 +00:00
ikelosandGitHub 03b2efa58f Merge pull request #659 from volatilityfoundation/issues/issue652-2
Objects: Don't try to read 0 bytes when unmarshalling
2022-02-26 13:26:09 +00:00
Mike Auty 1b09f20b5c Windows: Raise PE extraction size and make it a constant 2022-02-26 13:21:34 +00:00
Gustavo Moreira 643a8cc74c Make this method private using just a single leading underscore 2022-02-26 10:14:23 +11:00
Mike Auty 78b3553b2a Objects: Implement minor code optimization by @paulkermann 2022-02-25 16:33:54 +00:00
Mike Auty 265b282569 Objects: Don't try to read 0 bytes when unmarshalling 2022-02-23 22:53:54 +00:00