Commit Graph
5288 Commits
Author SHA1 Message Date
ikelosandGitHub 069a3da751 Merge pull request #504 from doomedraven/patch-1
ability to reverse filtering see long description
2021-05-23 16:58:35 +01:00
doomedravenandGitHub dd6ad75b22 Update pslist.py 2021-05-23 17:10:52 +02:00
Mike Auty abafa58f1a Windows: Increase self-referential check 2021-05-23 15:49:28 +01:00
Gustavo Moreira d6aba26aa7 fixing unsigned long size hardcoding 2021-05-22 09:14:38 +10:00
doomedravenandGitHub ed9c2dd979 ability to reverse filtering see long description
Hello, this is very useful to optimize some scans, like in case of sandboxing, imagine:
1 round it scans only all processes that was captured by sandbox aka pid_list
2. round it scans all the rest processes ignoring pid_list from round 1

if you have a better idea how to improve/implement this, let me know, we use our custom function, but i think it might be useful for the rest
2021-05-18 22:37:34 +02:00
Mike Auty 4cb71366c7 Windows: Improve netstat errors 2021-05-16 17:08:56 +01:00
Mike Auty f873ced04e Windows: Improve hashdumping plugin errors 2021-05-16 17:01:52 +01:00
Mike Auty 2705614306 Windows: Remove debugging statements from pdbutil 2021-05-13 21:49:25 +01:00
Gustavo Moreira b9d5ffd257 Kernel ring buffer reader plugin 2021-05-13 19:11:05 +10:00
ikelosandGitHub 8f7b0f2c47 Merge pull request #475 from f-block/develop
Temporary workaround for changes in transition PTE
2021-05-12 20:22:09 +01:00
iMHLv2 7152ca0ffc refactor load_segments() to fix 32-bit bitmap crashdumps 2021-05-11 15:59:42 -05:00
ikelosandGitHub 21b33b677c Merge pull request #496 from volatilityfoundation/feature/faster-pdb-scanning
Windows: Improve PDB scanning
2021-05-10 20:24:52 +01:00
Mike Auty 7d408ce0f3 Windows: Make IPI handling of PDBs optional 2021-04-26 01:16:38 +01:00
ikelosandGitHub a165b1b1cf Merge pull request #487 from volatilityfoundation/feature/better-windows-identification
Automagic: Add a slow scan for kernel identification
2021-04-22 18:00:56 +01:00
Mike Auty 007717590e Merge branch 'issues/issue495' into develop 2021-04-22 17:21:05 +01:00
Mike Auty e241ac0ac0 Windows: Fixes missing os import
Fixes #495
2021-04-22 17:18:52 +01:00
Mike Auty c5c726ab28 Windows: Improve PDB scanning 2021-04-21 00:02:36 +01:00
ikelosandGitHub 280c912121 Merge pull request #492 from cstation/fix/qemu-conf
Fix reading JSON configration of QEMU-images
2021-04-14 19:47:45 +01:00
cstation aa26601b34 Fix reading JSON configration of QEMU-images 2021-04-14 20:39:03 +02:00
Andrew Case f1d7d8610a Updates and bug fixes 2021-04-07 19:51:30 -05:00
Mike Auty 88ff4f1d06 Windows: Fix up double import in pdbconv 2021-04-07 22:30:45 +01:00
ikelosandGitHub 9d2c17b79d Merge pull request #483 from volatilityfoundation/prevent_pslist_backtrace
Prevent pslist from backtracing on invalid process.  Include a warnin…
2021-04-07 18:19:03 +01:00
Andrew Case 6f7d40f0cc Commit all requested changes except those related to array handling/creating 2021-04-07 12:06:31 -05:00
Andrew Case ce3b0fcc0b Change debug to info for invalid process warning message 2021-04-07 12:04:50 -05:00
Mike Auty 191da08fb3 Automagic: Add a slow scan for kernel identification 2021-04-04 17:46:37 +01:00
Mike Auty a1c5f5e5e5 Automagic: Improve secondary 64-bit self-ref finder 2021-04-03 13:33:20 +01:00
Mike Auty 087b172148 Automagic: Add secondary 64-bit self-referential value 2021-04-03 13:07:43 +01:00
iMHLv2 00db33e0fe print human readable dump type in crashinfo, along with bitmap header size, bitmap size, and page count 2021-03-31 09:52:12 -05:00
iMHLv2 fb54a2cade report segments in the crash layer with LOGLEVEL_VVVV 2021-03-30 21:23:46 -05:00
iMHLv2 3ebbddbd8d don't save objects in self
they contain a reference to the context, so if we ever pickle that, then it'll cause a massive recursion loop and fail
2021-03-30 21:12:32 -05:00
iMHLv2 f5e5fd0060 apply fixes and improvements for crash layer (see description)
1) Remove empty newlines before the license

2) Remove unused imports

3) Add support for 32-bit Bitmap crash dumps

4) Move _SUMMARY_DUMP to crash_common.json and fix the swapped Pages and BitmapSize offsets

5) Fix other errors in crash64.json (swapped SystemTime vs SystemUpTime, PsActiveProcessHead should be unsigned long long, several incorrect offsets for other members

6) Switched to new volatility3 namespace

7) Reverted required_framework_version to (1, 0, 0)

8) Fixed crashinfo plugin from unpacking the wrong number of values from layer.mapping(). Actually, the plugin no longer displays runs - it shows metadata instead.

9) Address Ikelos' comments in PR #452
2021-03-30 17:25:32 -05:00
iMHLv2 f4dee3c5f0 sync with fa1c03d of jxwegner/volatility3 2021-03-30 15:27:09 -05:00
Mike Auty f3c3e2c4f9 Windows: Don't try to delete URLs 2021-03-29 17:50:35 +01:00
ikelosandGitHub ef258ec010 Merge pull request #417 from volatilityfoundation/issues/optional-symbol-shift
Issues/optional symbol shift
2021-03-21 00:43:04 +00:00
Mike Auty 792fb7080c Symbols: Set symbol_shift default rather than None
Since all the checks for symbol_shift use essentially "if not
config['symbol_shift']" is doesn't matter whether 0 or None is
returned.  I'd like to test this on an ASLR image, but I think it should
be fine and I'd feel much happier about everything if we could give it a
numeric default.
2021-03-21 00:21:13 +00:00
Mike Auty 2402a51c60 Symbols: Make the symbol shift optional
The symbol_shift isn't quite as nice as it could be, because we use None
to demark an unset state, which is different than a value of 0 (because
unset will trip linux to try to identify, whereas 0 will not).

Every where we use the value, we get it from the dictionary and use 0 if
it's not found (essentially forcing a default), but ideally, the default
would be set.  As such, it's safe to set optional to true (and thus not
require it for configuration files), but it's not ideal that the linux
symbol finder can't determine whether to run or not without knowing
whether the value's been intentionally set...
2021-03-21 00:21:13 +00:00
ikelosandGitHub 6702595ebe Merge pull request #482 from volatilityfoundation/feature/better-strings-checking
Feature/better strings checking
2021-03-21 00:13:37 +00:00
ikelosandGitHub de78763e32 Merge pull request #480 from volatilityfoundation/feature/better-version-info
Windows: Add additional version info finding method
2021-03-21 00:11:40 +00:00
ikelosandGitHub 63101e6d0a Merge pull request #479 from volatilityfoundation/feature/directory-restructure
Windows: Group JSON symbols under directories
2021-03-21 00:10:43 +00:00
atcuno 68a6fd252f Fix typos and add more debug statements 2021-03-19 13:09:14 -05:00
atcuno 21b59e9458 Catch exceptions triggered during testing 2021-03-19 12:49:54 -05:00
atcuno 0be5dad2bd Prevent pslist from backtracing on invalid process. Include a warning with the offset. 2021-03-19 11:51:23 -05:00
Andrew Case d3b407515a Initial commit for mass testing 2021-03-19 11:29:19 -05:00
ikelosandGitHub 8e420dec41 Merge pull request #481 from volatilityfoundation/feature/version-pdbutility
Windows: Generalize symbol_table_from_pdb
2021-03-18 14:42:09 +00:00
Mike Auty ea71cbe9c9 Windows: Fix the verinfo versioning
This should already have been versioned because it had a classmethod.
Since it wasn't, we can start at (1, 0, 0) but it should only need
framrwork version (1, 0, 0) as well.
2021-03-17 21:02:55 +00:00
Mike Auty 9c30ed19ef Windows: Deprecate netstat create_tcpip_symbol_table 2021-03-17 20:07:29 +00:00
Mike Auty 8d8b2ea2dd Windows: Fix up hardcoded filename in pdbutil 2021-03-17 15:31:58 +00:00
Mike Auty 180087e746 Windows: Update vadyarascan with compiled file option 2021-03-15 22:58:48 +00:00
Mike Auty 88bddbd596 Windows: Clarify separate yara compiled method 2021-03-15 22:56:40 +00:00
ikelosandGitHub c75bef2b05 Merge pull request #477 from dadokkio/develop
enable support for compiled rules in Yara
2021-03-15 22:54:55 +00:00