Eve
0163f0b9e6
add linux.iomem plugin based on vol2 plugin by atcuno
2023-01-05 13:43:47 +00:00
Mike Auty
c1e425217b
Initial canonical helper addition
...
The intel 64-bit 4-page paging mechanism allows for 48-bit virtual
addresses. They introduced a convention that the higher bits must
be set a particular way to avoid operating system developers abusing
those bits and creating problems that would be difficult to resolve in
the future.
Volatility requires that addresses for mapping or translation fit within
the available bounds of the virtual address space. This unfortunately
means that addresses that have the protections against abuse in place
can may live outside this range.
This provides two function (canonicalize and decanonicalize) which will
either set the appropriate sign extension or remove it. The
decanonicalize function will return an adress outside of the address
range if the original value was not canonical.
2023-01-05 10:55:30 +00:00
Eve
4c0a0b923b
Update linux.proc --dump changes based on comments from ikelos
2023-01-04 16:05:00 +00:00
Eve
6f82e3d8cf
remove unused variable in linux.vmayarascan
2023-01-04 09:36:20 +00:00
Eve
f82a3f520f
liniting for linux.vmayarascan
2023-01-04 09:32:39 +00:00
Eve and GitHub
eb061175d1
Merge branch 'volatilityfoundation:develop' into linux_proc_dump
2022-12-21 07:03:22 +00:00
Eve
a553a69efd
fix linting issues
2022-12-21 06:42:02 +00:00
ikelos and GitHub
a6fb0f2ebc
Merge pull request #888 from volatilityfoundation/stable
...
Stable
2022-12-14 20:40:36 +00:00
ikelos and GitHub
d67ad9f8da
Merge branch 'develop' into stable
2022-12-14 20:18:45 +00:00
ikelos and GitHub
2b46e97e52
Merge pull request #887 from volatilityfoundation/release/v2.4.0
...
Prepare for the 2.4.0 release, the major version has jumped a few numbers for compatibility, but this is the next release including the following:
New plugins
linux.mountinfo
linux.psaux
windows.devicetree
windows.joblinks
windows.ldrmodules
windows.mbrscan
windows.mftscan
windows.sessions
Introduced the concept of modules and module requirements
Unified symbol handling and ISF file caching between OS versions
Better QEVM support (fixed the QEMU PCI hole)
Exposed an API for automatic PDB symbol table use
Improved contributed documentation
Various bug fixes and changes across the codebase
v2.4.0
2022-12-14 19:39:11 +00:00
Mike Auty
92ece08c5f
Core: Fix up file close issue
2022-12-14 18:51:09 +00:00
Eve
a68d56e191
add linux.vmayarascan based on windows.vadtarascan
2022-12-13 16:09:57 +00:00
Eve
53b24d33e0
First attempt at adding a --dump option to linux.proc, aim to be similar to windows.vadinfo --dump
2022-12-13 09:59:09 +00:00
Eve
92c7b3e550
add linux envars
2022-12-09 15:37:20 +00:00
ikelos and GitHub
057d314aa0
Merge pull request #879 from digitalisx/fix/runs-on-version
...
Fix: workflow `runs-on` version to `ubuntu-20.04`.
2022-12-08 16:20:07 +00:00
Donghyun Kim
632fe0b671
Fix: ubuntu version to 20.04
2022-12-09 01:00:16 +09:00
Donghyun Kim
5f4e2716db
Fix: ubuntu-latest version
2022-12-08 16:26:54 +09:00
Donghyun Kim and GitHub
06d70eb9b2
Merge branch 'volatilityfoundation:develop' into develop
2022-12-08 13:44:23 +09:00
Mike Auty
e67bac4080
Testing: Fix unclosed file open
2022-12-07 21:25:22 +00:00
Mike Auty
4cf0a185e3
Core: Bump minimum python 3 version for pypi build
2022-12-07 21:12:49 +00:00
Mike Auty
12109c6f72
Core: Fix up lint issue from pull request
2022-12-07 21:11:22 +00:00
Mike Auty
441be4535c
Core: Fix up black workflow action
2022-12-07 21:09:32 +00:00
ikelos and GitHub
02d6dbead7
Merge pull request #839 from digitalisx/fix/ssl-error-for-python37
...
Fix: unverified retrieval SSL Error for Python `3.7`.
2022-12-07 21:05:17 +00:00
ikelos and GitHub
a5799cc24c
Merge branch 'develop' into fix/ssl-error-for-python37
2022-12-07 21:05:10 +00:00
ikelos and GitHub
c73a1485b5
Merge pull request #838 from volatilityfoundation/feature/python-37
...
Core: Bump to python 3.7 with warnings for old global config variables
2022-12-07 21:04:17 +00:00
Mike Auty
66d63676ed
Core: Fix issue in constants code based on CodeQL result
2022-12-07 20:54:52 +00:00
ikelos and GitHub
b4e9e9203a
Merge branch 'develop' into feature/python-37
2022-12-07 20:50:40 +00:00
Mike Auty
bd402772c7
Core: Apply black to the entire codebase and add workflow
2022-12-07 20:48:14 +00:00
ikelos and GitHub
06ced0d59a
Merge pull request #855 from volatilityfoundation/drivermodule
...
Add drivermodule plugin and wrap common access to a Drver's names in …
2022-12-07 20:18:16 +00:00
Donghyun Kim and GitHub
a8b06b4ed9
Merge branch 'volatilityfoundation:develop' into fix/ssl-error-for-python37
2022-12-08 01:37:22 +09:00
ikelos and GitHub
b63424cec3
Merge pull request #727 from digitalisx/feature/vadwalk
...
Feature: implement `VADWalk` plugin.
2022-12-07 16:21:36 +00:00
ikelos and GitHub
7f666da4a1
Merge branch 'develop' into feature/python-37
2022-12-06 23:50:49 +00:00
Donghyun Kim and GitHub
566eacfd0f
Merge branch 'volatilityfoundation:develop' into feature/vadwalk
2022-11-30 13:12:08 +09:00
Mike Auty
e694713b20
Github: Backport action changes to 2.4.0 release
2022-11-30 01:05:25 +00:00
ikelos and GitHub
0ffd2067cd
Merge pull request #873 from digitalisx/fix/workflow
...
Fix: ubuntu `runs-on` version for workflow error.
2022-11-30 01:03:21 +00:00
Donghyun Kim and GitHub
27ac31d515
Merge pull request #5 from digitalisx/fix/workflow
...
Fix/workflow
2022-11-30 04:16:36 +09:00
Donghyun Kim and GitHub
3fda434520
Merge branch 'volatilityfoundation:develop' into fix/workflow
2022-11-30 04:10:59 +09:00
Donghyun Kim
130baa7f34
Remove: env for build
2022-11-30 04:10:40 +09:00
Donghyun Kim
7aaf157e07
Remove: env
2022-11-30 04:09:28 +09:00
Donghyun Kim
372003b0e4
Fix: more detail ubuntu version
2022-11-30 04:07:18 +09:00
Donghyun Kim
3daba5dabb
Fix: more detail version
2022-11-30 04:04:07 +09:00
Donghyun Kim
6e056a7819
Add: env value
2022-11-29 21:20:25 +09:00
Donghyun Kim
f7a4d4f1ef
Fix: 3.6.7 versions
2022-11-29 21:18:20 +09:00
Donghyun Kim
8c41007f0b
Fix: setup python method
2022-11-29 21:16:33 +09:00
Donghyun Kim and GitHub
cbdb08985e
Merge branch 'volatilityfoundation:develop' into feature/vadwalk
2022-11-29 21:07:38 +09:00
fc0fa30f9e
Update doc/source/getting-started-macos-tutorial.rst
...
Co-authored-by: Donghyun Kim <digitalisx99@gmail.com >
2022-11-20 10:18:47 +09:00
cpuu
53870c64d1
Add macos tutorial
2022-11-19 23:15:29 +09:00
cpuu
17bcc8d47e
typo
2022-11-19 23:11:45 +09:00
cpuu
b5c3ab171e
Add macos tutorial
2022-11-19 15:01:39 +09:00
Mike Auty
364a6a75f9
Windows: Fix bad use of strip
...
Close #867
2022-11-13 18:40:06 +00:00