Commit Graph
1106 Commits
Author SHA1 Message Date
Michael LighandMike Auty 7ae0d654c2 pass native_types to KdbgIntermedSymbols.create() instead of table_mapping 2018-06-12 08:41:37 +01:00
Michael LighandMike Auty ae9d7dbc86 use *args and **kwargs when inheriting from IntermediateSymbolTable 2018-06-12 08:41:37 +01:00
Michael LighandMike Auty 7797a6a385 add a class string to windows.info so that the plugin has a description 2018-06-12 08:40:21 +01:00
Michael LighandMike Auty fb57e2c5f2 wininfo, procdump, dlldump, and json for pe & kdbg 2018-06-12 08:40:21 +01:00
Mike Auty 2cbd444603 Add in symbol table address masker. 2018-06-06 23:12:46 +01:00
Mike Auty b228ad8e95 Add comment concerning reconstructability of SymbolTables. 2018-06-06 23:10:21 +01:00
Mike Auty 253304270b Ensure we can add native_types when we create tables. 2018-06-06 00:42:23 +01:00
Mike Auty 36dee38a9e Leave pointer out of the default types (since it needs an appropriate size). 2018-06-05 21:46:02 +01:00
Mike Auty 113c23a66d Last of the typing fix-ups. 2018-06-04 23:55:38 +01:00
Mike Auty 2dc3d2928d Fix more typing issues. 2018-06-04 23:28:26 +01:00
Dave Lassalleandikelos abfcdba524 add Windows 10 Registry process support 2018-06-04 20:17:28 +01:00
Mike Auty 816db6b626 Fix up some missing logging names that slipped through the review net. 2018-06-04 10:10:44 +01:00
Mike Auty 9711793503 Ensure intel.read(pad=True) doesn't return InvalidAddressExceptions. 2018-06-04 09:40:26 +01:00
Mike Auty f957b2915e Fix up issue having made optional parameters non-optional. 2018-06-04 09:39:38 +01:00
Mike Auty 7a52ac9deb Fix a large number of typing issues.
There are several instances where mypy didn't detect

if blah is not None:
    blah = thing

and so were rewritten as:

blah = blah or thing
2018-06-04 01:25:02 +01:00
Mike Auty d3782c0519 Fix typo as identified by @imhlv2. 2018-06-03 23:51:46 +01:00
Mike Auty 9740c4af84 Add in configwriter plugin, fixes issue #26. 2018-05-31 11:50:40 +01:00
Mike Auty 213c70527f Change the plugins option to plugin_dirs to avoid conflict with timeliner. 2018-05-31 11:48:12 +01:00
Mike Auty b647c3a089 Refactor volshell with inheritance and add dt.
It makes enourmous sense to inherit the windows volshell plugin from the
volshell one.  I also added the generic dt function.
2018-05-30 22:36:42 +01:00
Michael Ligh 17924a0667 refs #27 use _KLDR_DATA_TABLE_ENTRY on windows if its available 2018-05-30 13:55:20 -05:00
Mike Auty 6a6acd2dcc Move the table_mapping parameter to avoid disrupting the previous interface. 2018-05-30 18:37:29 +01:00
Mike Auty f72e39d558 Fix up small but significant typo.
When asking for data with padding, the padding was guaranteed to always
be at the end without spaces between pages.
2018-05-29 00:42:52 +01:00
Mike Auty 67239002bc Attempt to fix an intel read issue spotted by imhlv2
The length value inside the read method of the TranslationLayer base class
would potentially get overwritten by the inner loop which also defined a
length value.
2018-05-28 23:25:49 +01:00
Mike Auty 33b2c9522d Add in support for ISF.create to handle table_mappings. 2018-05-23 22:26:52 +01:00
Mike Auty a5df5372f5 Add in table_mapping through the ISF classes. 2018-05-23 22:23:32 +01:00
Mike Auty 1aa980169c Fix up the -f help message and tidy the code. 2018-05-23 22:12:47 +01:00
Mike Auty d6b7415bab Revert "Remove the -f flag before it gains too much use."
As @npetroni quite rightly pointed out, the purpose of the CLI is to
make it easy for people to use on the commandline, so at the expense of
some dynamic ability, -f is returning for convenience purposes.

This reverts commit 4450766d50.
2018-05-23 22:08:52 +01:00
Mike Auty 87d0f97f52 Remove the unnecessary exception and add in a better one. 2018-05-23 19:41:40 +01:00
Mike Auty 8bc5a4e898 Ensure maxaddr is never includes the volatile bit. 2018-05-23 19:41:13 +01:00
Mike Auty 347b4854ff Comment out the HBIN size check for now
Leave a comment to ensure we get back to checking out why the hbin size
check fails to only prevent bad accesses (and effectively gives false
positives).
2018-05-21 22:57:10 +01:00
Mike Auty 665db0017e Don't count the volatile bit when checking things are outside the hive maximum address. 2018-05-21 18:02:48 +01:00
Mike Auty 689756dc9a Deal with NULL base blocks in the registry code. 2018-05-20 23:25:20 +01:00
Mike Auty 4450766d50 Remove the -f flag before it gains too much use.
Given the single-location parameter is now a URIRequirement, and
can accept normal files (rather than a full URL), but is far more
accurate (it matches exactly what the automagic requests).  If there's
much uproar we can revert this one commit.
2018-05-15 00:54:13 +01:00
Mike Auty f8b592c236 Make the config path for plugins dynamic. 2018-05-15 00:11:31 +01:00
Mike Auty 61bf1d40b0 Fix scan_iterator parameter type. 2018-05-15 00:06:43 +01:00
Mike Auty 037ac28534 Move around the scanning functions and create an API for the iterators. 2018-05-14 01:03:43 +01:00
Michael Ligh 21b2eb7ecc malfind is reading chunks, not technically pages, so change PAGE_SIZE to CHUNK_SIZE 2018-05-13 18:49:11 -05:00
Michael Lighandikelos deb81aa1c8 address a few of @ikelos comments in the PR 2018-05-13 23:30:03 +01:00
Michael Lighandikelos a01e4e41b0 commit malfind 2018-05-13 23:30:03 +01:00
Mike Auty 04d609064a Remove TODO that's in the wrong place, and we've just to-done. 2018-05-13 21:32:05 +01:00
Mike Auty 63a1fb3690 Simplify intel scanning to ensure overlaps are handled correctly. 2018-05-13 20:57:11 +01:00
Mike Auty a07691b04f Ensure scanners don't return duplicates in the overlap. 2018-05-13 20:55:54 +01:00
Mike Auty 8b5c58fee9 Fix up slight intel scanner issue. 2018-05-13 15:46:02 +01:00
Mike Auty 44ca819869 Minor documentation tweaks. 2018-05-13 01:05:56 +01:00
Mike Auty 3ce9ad93c7 Fix return types for ModuleCollections. 2018-05-10 02:40:26 +01:00
Mike Auty 5c0140ed74 Fix typo in intel scanning engine. 2018-05-10 02:40:08 +01:00
Mike Auty 83eb346ba5 Clarify logic and fix an issue in intel scanning. 2018-05-10 02:13:46 +01:00
Mike Auty 19b8a0f696 Improve scan chunking for intel layers
We now use mapping to skip unmapped pages when scanning.  This
should be slightly quicker and likely more accurate.  We also now
don't chunk over the size requested by the scanner.  We don't quite
handle overlaps correctly yet (we overlap, but don't prevent
duplicates if the pattern is entirely within the overlap segment).
2018-05-09 23:32:58 +01:00
Mike Auty b791b6c1a1 Add an ignore_errors check for positive lengths. 2018-05-09 01:16:47 +01:00
Mike Auty 577b6c4b5b Fix strings not being displayed fully because they featured 'non-word' characters. 2018-05-08 23:59:59 +01:00