Mike Auty
|
b84a7abd37
|
Ensure we only offer the configuration options we use.
|
2018-08-28 22:39:40 +01:00 |
|
Mike Auty
|
244af47a2a
|
Swap inheritted config options for explicit config options.
|
2018-08-28 22:32:52 +01:00 |
|
Mike Auty
|
ec3c6f34b8
|
Convert malfind to classmethod convention (and fix a broken protect_values call).
|
2018-08-17 11:03:49 +01:00 |
|
Mike Auty
|
366269deb2
|
Refactor Module in interfaces to ModuleInterface.
|
2018-08-09 13:55:16 +01:00 |
|
Mike Auty
|
b1d46f843b
|
Convert documentation to napoleon/Google format docstrings.
|
2018-08-05 15:52:12 +01:00 |
|
Mike Auty
|
4897b7ab81
|
Fix up some typing errors.
|
2018-07-22 13:19:20 +01:00 |
|
 Michael Lighandikelos
|
3d7c10dd32
|
add the cmdline plugin for windows
|
2018-07-19 21:26:32 +01:00 |
|
Mike Auty
|
5906c76b1b
|
Fix omission where protect_values became a class method.
|
2018-07-17 21:15:41 +01:00 |
|
Mike Auty
|
0ebf11dcfa
|
Add typing information (and basic linting/formatting).
|
2018-06-25 00:18:02 +01:00 |
|
Mike Auty
|
d68d62e47d
|
Fix methodclass conversion for linux pslist.
|
2018-06-20 22:19:24 +01:00 |
|
 Michael Lighandikelos
|
ab6a9fa43b
|
add typing, catch more specific exceptions, raise pefile dependency issues, use classmethod
|
2018-06-19 09:59:28 +01:00 |
|
 Michael Lighandikelos
|
e4fbc82ab3
|
verinfo still needs the primary and nt_symbols requirements
|
2018-06-19 09:59:28 +01:00 |
|
 Michael Lighandikelos
|
c43c53a7d7
|
initial draft of verinfo
|
2018-06-19 09:59:28 +01:00 |
|
Mike Auty
|
70abef1f46
|
Rework how we handle import errors.
|
2018-06-19 09:58:09 +01:00 |
|
Mike Auty
|
4ca705a05c
|
Ensure the lack of yara doesn't kill volatility completely.
|
2018-06-17 20:39:29 +01:00 |
|
Mike Auty
|
f28ee6077e
|
Update for the new classmethod model.
|
2018-06-17 11:16:27 +01:00 |
|
Mike Auty
|
a1caf8d149
|
Add in initial VAD yarascan code.
|
2018-06-17 11:16:27 +01:00 |
|
Mike Auty
|
9c2ba66c53
|
Add in initial version of yarascan plugin.
|
2018-06-17 11:16:27 +01:00 |
|
Mike Auty
|
c0ec52822b
|
Add some typing fixes.
|
2018-06-16 14:19:36 +01:00 |
|
Mike Auty
|
60df83ef15
|
Convert modules/moddump to classmethod.
|
2018-06-16 14:03:22 +01:00 |
|
Mike Auty
|
ecb9d5cf05
|
Convert vadinfo calls to classmethods.
|
2018-06-16 13:38:48 +01:00 |
|
Mike Auty
|
c4c6d30d42
|
Rejig where the pslist plugin exists.
|
2018-06-16 13:38:48 +01:00 |
|
Mike Auty
|
ac8401991c
|
Convert all remaining plugins to use the new classmethod pslist.
|
2018-06-16 13:38:48 +01:00 |
|
Mike Auty
|
6ca34e6607
|
Start converting plugins to use classmethod pslist.
|
2018-06-16 13:38:48 +01:00 |
|
Mike Auty
|
aea59ffa34
|
Make the change for the core pslist (breaks lots of plugins).
|
2018-06-16 13:38:48 +01:00 |
|
 Dave Lassalleandikelos
|
09475d5992
|
set default value for key since we combined exception handling
|
2018-06-16 09:54:45 +01:00 |
|
 Dave Lassalleandikelos
|
c68d02d565
|
combine exception handling to reduce code duplication
|
2018-06-16 09:54:45 +01:00 |
|
 Dave Lassalleandikelos
|
b85c143af9
|
yield UnreadableValues when key not found, and set default RootCell on exception
|
2018-06-16 09:54:45 +01:00 |
|
 Dave Lassalleandikelos
|
481ea01149
|
catch the KeyError so we can iterate over all hives for a key path
|
2018-06-16 09:54:45 +01:00 |
|
Mike Auty
|
33e146533e
|
Fix minor typo in malfind.
|
2018-06-15 23:04:01 +01:00 |
|
 Michael Lighandikelos
|
7338cdbf8a
|
BaseDllName should be an UnreadableValue() if it cannot be accessed
|
2018-06-13 15:10:58 +01:00 |
|
 Michael Lighandikelos
|
3eeb48cc0e
|
add the moddump plugin for windows
|
2018-06-13 15:10:58 +01:00 |
|
Michael Ligh
|
95214216ea
|
BaseDllName and FullDllName should be UnreadableValue() if they cannot be accessed
|
2018-06-13 09:10:47 -05:00 |
|
Mike Auty
|
5f130a3b2a
|
Update timeliner and convert pslist to support it.
|
2018-06-12 09:01:01 +01:00 |
|
Mike Auty
|
eed92de9ef
|
Bulk of the modifications for the timeliner interface.
|
2018-06-12 09:01:01 +01:00 |
|
 Michael LighandMike Auty
|
7ae0d654c2
|
pass native_types to KdbgIntermedSymbols.create() instead of table_mapping
|
2018-06-12 08:41:37 +01:00 |
|
 Michael LighandMike Auty
|
7797a6a385
|
add a class string to windows.info so that the plugin has a description
|
2018-06-12 08:40:21 +01:00 |
|
 Michael LighandMike Auty
|
fb57e2c5f2
|
wininfo, procdump, dlldump, and json for pe & kdbg
|
2018-06-12 08:40:21 +01:00 |
|
Mike Auty
|
2dc3d2928d
|
Fix more typing issues.
|
2018-06-04 23:28:26 +01:00 |
|
Mike Auty
|
816db6b626
|
Fix up some missing logging names that slipped through the review net.
|
2018-06-04 10:10:44 +01:00 |
|
Mike Auty
|
d3782c0519
|
Fix typo as identified by @imhlv2.
|
2018-06-03 23:51:46 +01:00 |
|
Mike Auty
|
9740c4af84
|
Add in configwriter plugin, fixes issue #26.
|
2018-05-31 11:50:40 +01:00 |
|
Michael Ligh
|
17924a0667
|
refs #27 use _KLDR_DATA_TABLE_ENTRY on windows if its available
|
2018-05-30 13:55:20 -05:00 |
|
Mike Auty
|
87d0f97f52
|
Remove the unnecessary exception and add in a better one.
|
2018-05-23 19:41:40 +01:00 |
|
Mike Auty
|
689756dc9a
|
Deal with NULL base blocks in the registry code.
|
2018-05-20 23:25:20 +01:00 |
|
Mike Auty
|
f8b592c236
|
Make the config path for plugins dynamic.
|
2018-05-15 00:11:31 +01:00 |
|
Michael Ligh
|
21b2eb7ecc
|
malfind is reading chunks, not technically pages, so change PAGE_SIZE to CHUNK_SIZE
|
2018-05-13 18:49:11 -05:00 |
|
 Michael Lighandikelos
|
deb81aa1c8
|
address a few of @ikelos comments in the PR
|
2018-05-13 23:30:03 +01:00 |
|
 Michael Lighandikelos
|
a01e4e41b0
|
commit malfind
|
2018-05-13 23:30:03 +01:00 |
|
Mike Auty
|
577b6c4b5b
|
Fix strings not being displayed fully because they featured 'non-word' characters.
|
2018-05-08 23:59:59 +01:00 |
|