Mike Auty
81653dba6d
Registry: Ignore errors if ignore_errors is set.
2020-01-17 01:14:09 +00:00
Mike Auty
8f71c61440
layerwriter: Fix mistaken hardcoded layer name.
2020-01-16 23:07:27 +00:00
Mike Auty
99af98f639
layerwiter: Refactor to classmethod.
2020-01-16 22:57:47 +00:00
Mike Auty
572313cc34
Objects: Make sure bytes provide a template size.
2020-01-16 11:06:16 +00:00
Mike Auty
a3def09a13
Registry: Optimize calls to DataLength and improve documentation.
2020-01-15 22:59:58 +00:00
Mike Auty
cedca0bb84
Objects: Document void size a little more.
2020-01-15 21:55:30 +00:00
Mike Auty
2d408491bd
Printkey: Slightly improve subkey name determination.
2020-01-15 02:19:12 +00:00
Mike Auty
3f5b96f3c7
Yapf: Clean-up the whole codebase.
2020-01-14 15:44:07 +00:00
Mike Auty
b7ba877727
procdump: Enure proc_id is defined.
2020-01-14 15:36:54 +00:00
doomedraven and ikelos
07b94abc1e
Update procdump.py
2020-01-14 10:52:05 +00:00
doomedraven and ikelos
cdc0835863
Update procdump.py
2020-01-14 10:52:05 +00:00
doomedraven and ikelos
e4d7b7975f
expose process_dump to other plugins
2020-01-14 10:52:05 +00:00
Mike Auty
fda64dde95
Mac tasks: Swap the shortcircuiting order
2020-01-13 14:13:37 +00:00
Mike Auty
8a03cf53f0
Objects: Ensure templates objects aren't ReferenceTemplates.
2020-01-13 13:58:35 +00:00
Mike Auty
b4a9937da7
Objects: Void has no size, and BitFields don't inherit from Integer.
2020-01-13 02:16:35 +00:00
Mike Auty
0f49673aa0
Objects: Ensure string template objects return the right size.
2020-01-13 01:41:57 +00:00
Mike Auty
3977a3c356
objects: Fixes for the comments in #159
2020-01-10 12:47:06 +00:00
Mike Auty
d969d89da9
Objects: Ensure array sizes change with their count
2020-01-10 12:47:06 +00:00
Mike Auty
fba6511486
Objects: Add size to ObjectInfo so it can be statically access later
2020-01-10 12:47:06 +00:00
Michael Ligh and ikelos
e80e9e09b6
the hand-written 32-bit windows 10 service record types were missing the Tag member
2020-01-05 01:53:52 +00:00
iMHLv2 and GitHub
f7cc94a244
Merge pull request #168 from volatilityfoundation/issue-10-vad-protection-layer
...
Use a kernel layer to read vad protection constants
2020-01-04 10:02:59 -06:00
Michael Ligh
b7b6c44eab
remove unused variable in vaddump.py
2020-01-04 09:35:51 -06:00
iMHLv2 and GitHub
af468e7657
Merge pull request #162 from Lyx09/fix_vad_dump_var
...
VadDump: Fix incorrect variable out_of_range in vad_dump
2020-01-04 09:34:25 -06:00
Mike Auty
d2daa12564
Malfind: Rename the layer_name parameter to be more descripttive
2020-01-03 22:12:04 +00:00
Daniel Milnes and ikelos
f573f22721
Add issue templates
2020-01-03 22:06:23 +00:00
Andrew Case and ikelos
d7f5a13c46
Mac - properly check for broken proc pointers
2020-01-03 19:42:18 +00:00
Andrew Case and ikelos
3bf3e0601a
Remove earliler trigger of SymbolError
2020-01-03 17:50:06 +00:00
Andrew Case and ikelos
a66e1bb6c2
Move symbol catching to generator
2020-01-03 17:50:06 +00:00
Andrew Case and ikelos
65556a2c92
Linux - update handling of kernels that do not have loadable module support
2020-01-03 17:50:06 +00:00
Mike Auty
fc005d08cc
CLI: Fix issue #163 , incorrect parallelism option
2019-12-28 21:21:55 +00:00
William LIN
e6656c96af
VadDump: Fix incorrect variable out_of_range in vad_dump
2019-12-26 19:51:13 +01:00
Mike Auty
604e8adcbc
Renderers: Fix up the JSON renderer's timedate formatting
2019-12-16 21:58:22 +00:00
Mike Auty
681da142c5
Renderers: Split JSON output into JSON and JSONL
2019-12-16 21:58:22 +00:00
Mike Auty
fc5062fbe0
Renderers: Don't include the title in JSON output.
2019-12-16 21:58:22 +00:00
Mike Auty
0746fd2994
Add in JSON renderer.
2019-12-16 21:58:22 +00:00
Mike Auty
348ac4e41b
Layers: Remove while true Take 2.
2019-12-11 20:04:30 +00:00
Mike Auty
a8a467a0c3
Revert "Layers: Remove (horrible, horrible) uses of while true in the codebase (my bad)"
...
This reverts commit a963938e11 .
2019-12-11 19:56:29 +00:00
Mike Auty
a963938e11
Layers: Remove (horrible, horrible) uses of while true in the codebase (my bad)
2019-12-11 19:42:10 +00:00
Michael Ligh
cd841616af
refs #144 use a kernel layer to read vad protection constants
2019-12-08 07:46:02 -06:00
Mike Auty
83a8afba6b
Objects: Simplify get_symbol_table to get_symbol_table_name.
2019-12-04 23:41:27 +00:00
Mike Auty
fa26dbf659
Yarascan: Make generic yarascan just scan kernel memory.
2019-12-04 23:17:10 +00:00
Mike Auty
f34958a16d
Poolscanner: Add necessary exception handling.
2019-12-04 22:11:42 +00:00
Mike Auty
386f94d9ee
Pool: Make object_header type checking the plugin's responsibility.
2019-12-04 22:11:42 +00:00
Mike Auty
8691c68604
Pool: Refactor pool extension to its own file.
2019-12-04 22:11:42 +00:00
Michael Ligh and ikelos
d0f9cf9a2f
refs #139 use _EPROCESS.ControlFlowGuardEnabled to distinguish between windows 10 <= 15063 versus >= 16299
2019-12-04 21:19:19 +00:00
Mike Auty
1eea645da0
EPROCESS: Wrap get_peb functions in error handlers
2019-12-04 21:13:19 +00:00
Mike Auty
17247426d8
pdbconv: Avoid more name-collisions
...
Previously we allow name-collisions for types with name <anonymouos-tag>
so this has now been resolved, as well as descending too deeply down the
type to tree determine the size of array occassionally.
2019-12-04 20:04:22 +00:00
xabiugarte and ikelos
35abb343da
Raise exception instead of return None
2019-12-04 20:02:31 +00:00
xabiugarte and ikelos
3545ab7746
Fixes on pydoc, types, exception catching
2019-12-04 20:02:31 +00:00
xabiugarte and ikelos
c9520dc37f
Remove extra line
2019-12-04 20:02:31 +00:00