Commit Graph
4482 Commits
Author SHA1 Message Date
Andrew Case 802fc024b5 switch api place 2024-09-06 13:27:04 -05:00
Andrew Case 61cf58d977 black fixes 2024-09-06 12:49:01 -05:00
Andrew Case fd87772877 Move VAD enumeration into pe_symbols 2024-09-06 12:47:42 -05:00
Andrew Case bcd93616c0 more black help 2024-09-06 12:36:35 -05:00
Andrew Case 7b48ee4be4 more black help 2024-09-06 12:36:13 -05:00
Andrew Case c223ac6e76 more black help 2024-09-06 12:31:55 -05:00
Andrew Case 30cb5bd3ab Formatting that my local black doesn't understand 2024-09-06 12:14:06 -05:00
Andrew Case 3bb9264a57 formatting 2024-09-06 12:11:16 -05:00
Andrew Case 69e6e59daf Add new pe_symbols API, debug registers plugin, unhooked system calls plugin 2024-09-06 12:01:21 -05:00
ikelosandGitHub d56cd83510 Merge pull request #1225 from volatilityfoundation/orphan_threads_v2
Orphan threads v2
2024-09-03 20:50:06 +01:00
ikelosandGitHub 6803bf375b Merge pull request #1249 from volatilityfoundation/mft_size_smear_fix
Mft size smear fix
2024-09-03 20:48:04 +01:00
Andrew Case 9c058936a8 Address feedback 2024-09-03 10:30:05 -05:00
ikelosandGitHub a40ac64572 Merge pull request #1247 from Abyss-W4tcher/archs_spec_unification
[core, constants] : add OS and framework supported architectures
2024-09-02 22:11:30 +01:00
ikelosandGitHub 3f5fce31e7 Merge pull request #1208 from dadokkio/develop
yara-x support for yarascan
2024-09-02 21:51:50 +01:00
Andrew Case 660e8a7b89 Add smear checks in MFT parsing code 2024-09-02 15:09:20 -05:00
Andrew Case 483cb7e4ee Add smear checks in MFT parsing code 2024-09-02 15:08:29 -05:00
Andrew CaseandGitHub c4cc50ea48 Merge branch 'develop' into orphan_threads_v2 2024-09-02 12:18:15 -05:00
Andrew Case 46a26c7dc5 Address feedback 2024-09-02 12:17:16 -05:00
Abyss Watcher 7a479d617f add OS and framework architectures constants 2024-08-28 18:40:41 +02:00
Davide Arcuri a2196850bc increase python version to 3.8 2024-08-28 10:39:28 +02:00
ikelosandGitHub 517f46e833 Merge pull request #1245 from volatilityfoundation/issues/fix-broken-1173-vesion-bump
Bump the modules version number
2024-08-28 08:07:41 +01:00
Mike Auty 6a157a785f Bump the modules version number
Pull-request #1173 bumped the version of the modules plugin (even though
this only needed to be a MINOR version bump, see
https://github.com/volatilityfoundation/volatility3/pull/1173#discussion_r1649614761), but failed
to verify that other plugins which relied on it were also updated to
make use of the new plugin.  This was the version system working as
intended, but highlighted a review failure that the neither the author, nor the
reviewers, verified that the rest of the framework (specifically other plugins which
relied on modules) worked correctly with the new code (which this kind
of error is designed to fix).

Fixes #1244.
2024-08-27 14:45:55 +01:00
ikelosandGitHub c524d8a3d1 Merge pull request #1242 from volatilityfoundation/issues/fix-up-extension-verisioning
Remove get_vmlinux calls
2024-08-25 12:28:29 +01:00
Mike Auty e97abae156 Remove get_vmlinux calls
Sorry, I know I asked for it, but I hadn't quite figured out what was
going on.  Things in the symbols/linux code are considered part of the
framework, and therefore it's the framework version that should have been
bumped.  Since the framework comes packages with LinuxUtilities we can
rely on the version numbers to be suitable.  This cleans up the mess I
caused, sorry for the extra work!  5:S
2024-08-24 15:02:37 +01:00
ikelosandGitHub 966d23e301 Merge pull request #1233 from gcmoreira/linux_page_cache
Linux Page Cache and IDR
2024-08-24 14:43:35 +01:00
Gustavo Moreira 3bf9f8cec0 PR review fixes: Add typing info to pagecache.Files._follow_symlink() 2024-08-24 12:03:10 +10:00
Gustavo Moreira 90b327e632 PR review fixes: Make mountinfo.get_superblocks() a classmethod and adapt the code using it. 2024-08-24 11:45:29 +10:00
Gustavo Moreira d627f243e2 PR review fixes: Add typing info to the get_inodes() class method. 2024-08-24 10:55:01 +10:00
Gustavo Moreira d964e6f61d PR review fixes: Check for LinuxUtilities version everywhere we use it 2024-08-24 02:06:06 +10:00
Gustavo Moreira 695635199e PR review fixes: Avoid saving state in the pidhashtable plugin 2024-08-24 01:14:09 +10:00
Gustavo Moreira 3c70c1b9f7 PR review fixes: Use context and module_name instead of vmlinux in ebpf plugin 2024-08-24 00:58:04 +10:00
Gustavo Moreira feae6a9aa0 PR review fixes: Use plugin's open method instead of the builtin open() 2024-08-24 00:42:52 +10:00
ikelosandGitHub 9bba6287a2 Merge pull request #1213 from forensicxlab/feature/lsof_inodes
Improvement: Linux/lsof
2024-08-22 23:45:20 +01:00
k1nd0ne 71cdca5883 Updating version + docstring 2024-08-22 16:45:04 +02:00
Mike Auty 8d7edfdca6 Bump as the release branch has been cut 2024-08-21 20:36:09 +01:00
ikelosandGitHub 4578434bbd Merge pull request #1236 from sluke-nuix/issues/truecrypt_module_version
Update the modules.Modules version requirement.
2024-08-13 17:06:46 +01:00
Steven Luke 918584537f Update the modules.Modules version requirement.
This is a response to PR [#1173](https://github.com/volatilityfoundation/volatility3/pull/1173)
2024-08-13 08:34:35 -04:00
Gustavo Moreira 7efa2210a5 PR review fixes: Adjust LinuxUtilities version since we moved choose_id_storage() back to the IDStorage class. 2024-08-13 01:05:44 -07:00
Gustavo Moreira f804b44ff6 Fix test.yaml, it should remove *.bin and not *.lime. There is no *.lime atm. 2024-08-13 01:00:57 -07:00
Gustavo MoreiraandGitHub b69c2c762c Merge branch 'volatilityfoundation:develop' into linux_page_cache 2024-08-10 06:05:33 -03:00
Gustavo Moreira 8f9d565f63 PR review fixes: Fix minor typo to match verb form from other docstrings 2024-08-10 00:49:18 -07:00
Gustavo Moreira 17861618df PR review fixes: Rename Tree to IDStorage. Move choose_id_storage() form LinuxUtilities to IDStorage. Use context and kernel_module_name instead of vmlinux 2024-08-10 00:13:38 -07:00
Gustavo Moreira 53f3d12341 linuxutilities code improvement. Remove code duplication 2024-08-09 23:35:41 -07:00
k1nd0ne f22575669a Modifications following the review 2024-08-09 10:20:28 +02:00
Gustavo Moreira 2c85ea525e PR review fixes: Fix page extension object get_content() explicit returns mixed with implicit returns. 2024-08-08 02:03:28 -07:00
Gustavo Moreira 06508a4afb PR review fixes: Fix the IDR's old kernel get_entries 2024-08-08 02:00:27 -07:00
Gustavo Moreira 7a8dea3356 PR review fixes: Code scanning complains about these unused variables. Let's comment them and adapt the FIXME message 2024-08-08 01:57:35 -07:00
Gustavo Moreira 0f3f338633 PR review fixes: Since the IDR, XArray and RadixTree can store any value, it renames the function names to a more generic name 2024-08-08 01:52:57 -07:00
Gustavo Moreira ee10ba8abb PR review fixes: Fix IDR explicit returns mixed with implicit returns and improve and fix code. 2024-08-08 01:46:53 -07:00
Gustavo Moreira de6637c987 PR review fixes: ebpf plugin code improvement. Use the object_from_symbol() instead 2024-08-08 00:52:34 -07:00