Commit Graph
311 Commits
Author SHA1 Message Date
Mike Auty b07ce5bd38 Crash64: Add support for type 0x01 to crashdump64 2020-09-23 20:28:23 +01:00
Mike Auty 31e251e108 Layers: Initial crashdump64 implementation 2020-09-23 20:28:23 +01:00
memoryforensics1andikelos d1264e0134 Update __init__.py 2020-09-22 18:30:54 +01:00
memoryforensics1andikelos 30be4ee2ec fix get_sids function
fix get_sids function in broken images
2020-09-22 18:30:54 +01:00
lyles6andikelos 85775239b5 changed back to same format as get_parent 2020-09-10 09:13:31 +01:00
slyles1001andikelos 720f46a962 provides for vadnode and core 2020-09-10 09:13:31 +01:00
Mike Auty 6b9ec5a079 Poolscanner: More native_layer validity checks 2020-09-08 02:45:20 +01:00
Mike Auty b04329e2e9 Poolscanner: Ensure File.Buffer checks right layer 2020-09-08 02:23:32 +01:00
memoryforensics1andikelos 37de4d45e7 fix 2020-09-02 10:52:53 +01:00
memoryforensics1andikelos 74f1492097 fix 2020-09-02 10:52:53 +01:00
memoryforensics1andikelos 2408f26f1f fix, add cross_thread_flags to ETHREAD struct 2020-09-02 10:52:53 +01:00
memoryforensics1andikelos 6be5716195 Add FILE_OBJECT and EPROCESS extestions, kthread, token struct
add functionality to:
FILE_OBJECT:
         access_string function
EPROCESS:
         environment_variables function

new structs:
TOKEN:
         get_sids function
         privileges funciton
KTHREAD:
         get_state function
         get_wait_reason function
2020-09-02 10:52:53 +01:00
memoryforensics1andikelos 489dd0cf77 add KTHREAD struct 2020-09-02 10:52:53 +01:00
memoryforensics1andikelos 6487eb5596 Add FILE_OBJECT and EPROCESS extestions, kthread, token struct
add functionality to:
FILE_OBJECT:
         access_string function
EPROCESS:
         environment_variables function

new structs:
TOKEN:
         get_sids function
         privileges funciton
KTHREAD:
         get_state function
         get_wait_reason function
2020-09-02 10:52:53 +01:00
memoryforensics1andikelos 8a3ee4f0b7 add token object
_TOKEN struct added
2020-09-02 10:52:53 +01:00
Mike Auty 88214527ab PdbUtility: Fixes from npetroni (and restore progress) 2020-09-01 09:02:13 +01:00
Mike Auty b9e0670e90 PDBUtility: Refactor this to a more central place 2020-09-01 09:02:13 +01:00
AsafEitaniandikelos 7ab72a1066 yapf and some corrections 2020-08-31 17:05:20 +01:00
Mike Auty ebad953a74 Windows: Refactor winver to versions. 2020-08-29 10:58:16 +01:00
Mike Auty 567cded35f Windows: Fix OsDistinguisher typo 2020-08-29 10:58:16 +01:00
Mike Auty 6e816c2f20 Windows: Convert os_distinguisher to callable class 2020-08-29 10:58:16 +01:00
Mike Auty 71366cde33 Windows: Refactor the location of os_distinguisher 2020-08-29 10:58:16 +01:00
Janandikelos b82aadeddf bumps version number due to api change, clarifies code 2020-08-24 19:03:28 +01:00
Janandikelos 6b8c9ff024 removes unnecessary enum, incorporates has_valid_member and emphasises max and min year for validation 2020-08-24 19:03:28 +01:00
Janandikelos db04a29185 removes additional TCP state enum 2020-08-24 19:03:28 +01:00
Janandikelos 46b5e29500 adds netscan plugin, network objects extension and symbol JSONs 2020-08-24 19:03:28 +01:00
Dave Lassalleandikelos 09ca2ecb40 issue #306 - _POOL_HEADER class based on OS 2020-08-22 22:27:46 +01:00
Mike Auty 75719c8393 Pdbconv: Improve typing without recording unnamed types 2020-08-17 23:09:13 +01:00
Mike Auty bd591bd5d8 Pdbconv: Revert typing correction that causes breakages 2020-08-17 17:10:47 +01:00
Mike Auty 8e420cbe62 Core: Multiple typing fixes across the tree 2020-08-16 22:22:24 +01:00
Mike Auty 31600254b9 Codebase: Apply yapf across the codebase. 2020-07-23 01:31:41 +01:00
Dave Lassalleandikelos 42a97dd10c Registry: handle ints, multi strings, and binary data with StrLike 2020-07-16 19:44:18 +01:00
Mike Auty 9a4669881d Registry: Move StringLike from conversion to StrLike format_hint. 2020-07-16 19:44:18 +01:00
Mike Auty eb90d4e830 Registry: Retain data recovered from registry strings 2020-07-16 19:44:18 +01:00
Mike Auty 5571f19b09 Registry: Move StringLike from conversion to StrLike format_hint. 2020-07-16 19:44:18 +01:00
Mike Auty ee41e7968f Registry: Retain data recovered from registry strings 2020-07-16 19:44:18 +01:00
Mike Auty c21bc62589 Pdbconv: Fix issue when remote file does not exist 2020-07-15 21:42:46 +01:00
Michael Lighandikelos 87ff6dd87c refs #200 raise ValueError if an object doesn't have a name 2020-07-01 20:51:22 +01:00
Mike Auty d6741435ef SymbolTables: Clear out the clone method and tidy up inheritance 2020-06-10 19:39:20 +01:00
Mike Auty a0da5fef83 Issue #186: Rebase and apply yapf 2020-05-27 23:16:18 +01:00
superponibleandikelos a21ab89019 issue #186 - add bigpools plugin 2020-05-27 23:16:18 +01:00
superponibleandikelos e969f44471 issue #186 - _CMHIVE.is_valid() 2020-05-27 23:16:18 +01:00
Mike Auty 0c43beb42d Core: Apply yapf across all files again. 2020-05-05 22:14:33 +01:00
Tamas K Lengyelandikelos 6a6cf37b02 pdbconv: save _imp functions in JSON 2020-02-14 09:20:15 +00:00
Michael Lighandikelos 4c7f2a3762 catch InvalidAddressException when traversing left and right child VADs (triggered on terminated processes) 2020-02-12 19:19:27 +00:00
Mike Auty 7873a65999 Procdump: Don't loop through twice without good reason. 2020-02-12 19:07:24 +00:00
Mike Auty a3def09a13 Registry: Optimize calls to DataLength and improve documentation. 2020-01-15 22:59:58 +00:00
Michael Lighandikelos e80e9e09b6 the hand-written 32-bit windows 10 service record types were missing the Tag member 2020-01-05 01:53:52 +00:00
Mike Auty 83a8afba6b Objects: Simplify get_symbol_table to get_symbol_table_name. 2019-12-04 23:41:27 +00:00
Mike Auty 386f94d9ee Pool: Make object_header type checking the plugin's responsibility. 2019-12-04 22:11:42 +00:00