Mike Auty
7efe19224e
Make several small typing information fixes.
2019-09-17 18:01:11 +01:00
Mike Auty
33451967b2
Typing fixes for virtmap and remove extranious exception.
2019-09-17 17:58:47 +01:00
superponible and ikelos
ae8822dddf
check if hive offset is valid before yielding
2019-09-17 16:59:50 +01:00
superponible and ikelos
2fa9e6b84d
fix typo in comment
2019-09-17 16:59:50 +01:00
superponible and ikelos
508a9148ed
catch InvalidAddressException when creating RegistryHive
2019-09-17 16:59:50 +01:00
superponible and ikelos
36f5e47d5b
fix up docstrings to match yield values
2019-09-17 16:59:50 +01:00
Mike Auty
c6cdbc7342
Move the hive_iterator to HiveList, since it's more intuitively where it should live.
2019-09-17 16:59:50 +01:00
Mike Auty
b292188319
Update userassist to use the new printkey API.
2019-09-17 16:59:50 +01:00
Mike Auty
46c047b7b3
Update API slightly to return objects not strings.
2019-09-17 16:59:50 +01:00
Mike Auty
b413e4a13d
Refactor printkey to be more usable from other plugins.
2019-09-17 16:59:50 +01:00
Mike Auty
10cf65fb60
Add in better documentation for callbacks.
2019-09-10 00:43:44 +01:00
Michael Ligh and ikelos
4e3db7a3de
add PluginRequirements for ssdt and svcscan. add missing _version to svcscan
2019-09-08 16:08:48 +01:00
Michael Ligh and ikelos
1d7f2a9582
use ntkrnlmp.object() instead of context.object(). remove config_path argument to list* functions
2019-09-08 16:08:48 +01:00
Michael Ligh and ikelos
50548bac73
reformat with yapf
2019-09-08 16:08:48 +01:00
Michael Ligh and ikelos
e71b72b3a7
add the windows callbacks plugin
2019-09-08 16:08:48 +01:00
Mike Auty
421af88c29
Classmethod make_subconfig so other classmethods can use it.
2019-09-08 14:50:48 +01:00
Mike Auty
03bc3d927d
Improve the name of a handles exposed function.
2019-09-08 13:22:42 +01:00
Mike Auty
3318e9c4a5
Fix a typo introduced in 5362e2094e.
2019-09-08 01:58:46 +01:00
Mike Auty
189b8c4d69
Update the windows info plugin with classmethods.
2019-09-07 23:00:41 +01:00
Mike Auty
e922cef316
Improve docstrings for all plugins, and reformat all docstrings.
2019-09-07 22:59:54 +01:00
Mike Auty
dc0a809729
Printkey: Don't offer two options for the same value.
2019-09-07 22:05:09 +01:00
Mike Auty
959e1617fd
Shift one-time checks out of loops.
2019-09-07 12:40:32 +01:00
Mike Auty
b158c58310
Ensure non-found keys mimic found key output a little closer.
2019-09-01 22:44:42 +01:00
Mike Auty
952a1b9d69
Move printkey recursion around to get proper tree depth.
2019-09-01 16:17:26 +01:00
Mike Auty
f040ceed96
Ensure keys and values are at the same level.
2019-09-01 16:10:58 +01:00
Mike Auty
3d7b2a520b
Ensure the tree output for printkey doesn't jump into deep layers.
2019-09-01 16:05:51 +01:00
Mike Auty
c2feba6651
Remove debugging calls from layerwriter plugin.
2019-09-01 15:50:29 +01:00
Mike Auty
39c4d061a1
Convert registry.printkey hive_walker to a class method.
2019-08-31 14:32:35 +01:00
Mike Auty
a3caf39097
Use a mapping to determine kind to class.
2019-08-31 12:57:53 +01:00
Mike Auty
35dbdfc69d
Add in PluginRequirement for proc_maps plugin.
2019-08-27 23:35:19 +01:00
Mike Auty
a9853eca50
Fix the copyright headers (and yapf) in the mac plugins.
2019-08-27 23:34:06 +01:00
Andrew Case and ikelos
6b4c13089d
add mac_proc_maps
2019-08-27 23:31:01 +01:00
Andrew Case and ikelos
07ece011a3
Add mac_tasks
2019-08-27 23:28:51 +01:00
Mike Auty
9cde94bceb
Change the license blurb on all files.
2019-08-27 23:11:00 +01:00
Mike Auty
42b2fb120a
Swap TranslationLayerInterface decendents over to LinearMappedLayers
2019-08-27 21:09:13 +01:00
Mike Auty
71bb54379b
Refactor the plugin versioning to be simpler to define.
2019-08-27 21:08:29 +01:00
Mike Auty
47c349e240
Add plugin requirements for all plugins.
2019-08-27 21:08:29 +01:00
Mike Auty
58dffe8795
Fix typos from the rebase, and add documentation.
2019-08-27 21:08:29 +01:00
Mike Auty
a58f064ea8
Rework how the plugin_version is checked.
2019-08-27 21:08:29 +01:00
Mike Auty
11fc8654e3
Initial attempt at plugin versioning.
...
So this allows people to alter the APIs for their plugins and allows
plugins to verify the API is compatible with the one they expect.
It adds a version property to Plugin classes, and has a SemVer checking
method which can be called from other plugins to verify a plugin against
a particular version.
2019-08-27 21:08:29 +01:00
Mike Auty
6fc12e9b01
Make sure options are specific to each plugin.
...
So this feels like a contentious decision. It'd be awesome to have the
options for the methods stored along-side the methods themselves.
The downside with this is that the thing accessing the configuration
data is always the plugin, so it's the plugin that must have requested
the configuration option. This is also important in case the
description of the configuration option needs modifying for clarity or
providing context for how it will be used.
If the interface changes, all plugins calling the plugin methods will
need updating, so the config options can be updated if necessary.
2019-08-23 21:41:50 +01:00
Mike Auty
d0b0a96ac1
Refactor the run_plugin method to more accurate construct_plugin.
2019-08-20 00:13:00 +01:00
Mike Auty
c0f650ba78
Ensure Mac plugins are documented and add complex tasks documentation.
2019-08-18 22:35:34 +01:00
Mike Auty
37e13321f9
Fix warnings when generated documentation.
2019-08-18 18:30:44 +01:00
Mike Auty
57510803d5
Fix up an issue when removing PoolHeaderSymbolTable.
2019-08-18 01:19:34 +01:00
Mike Auty
1082429aab
Don't use a separate symbol table class just to add a class override.
2019-08-17 23:20:46 +01:00
Mike Auty
35d8faae83
Add in exception throwing if case of no valid response.
2019-08-15 22:09:41 +01:00
Mike Auty
433e40a606
Support some middling versions of windows 10 in virtmap.
2019-08-15 21:49:21 +01:00
Mike Auty
287c7ce0b0
Minor fixes for virtmap given the recent module refactoring.
2019-08-15 21:05:49 +01:00
Mike Auty
8ccf8b045d
Add in first draft of virtmap plugin.
2019-08-14 20:53:45 +01:00