Mike Auty
bca972f28a
Remove the python implementation of __getattribute__ for speed.
...
The __getattribute__ method is called for *all* attribute lookups, and
the python implementation is likely slow. The only function the python
implementation provided was to check that properties started with
helper_. Since this only provided a log message, we could add it back
in only if the log level is high enough? Either way, it's not
significant enough to warrant costing extra time in every attribute
lookup on every object.
2018-07-30 23:58:02 +01:00
Mike Auty
552101b593
Attempt to reduce the amount of time taken in calling templates.
2018-07-30 23:53:00 +01:00
Mike Auty
79d2bab44d
A few additional typing fixes.
2018-07-22 13:29:43 +01:00
Mike Auty
4897b7ab81
Fix up some typing errors.
2018-07-22 13:19:20 +01:00
Mike Auty
b6b4c44300
Ensure cross-platform support for linux_cache.
2018-07-22 11:55:10 +01:00
Mike Auty
2f3f291e53
Fix up missing parameter in symbol_space.
2018-07-19 09:54:56 +01:00
Mike Auty
2f28dfa6c9
Support finding symbols by ranges.
2018-07-19 09:51:51 +01:00
Mike Auty
083fd43890
Ensure get_module_symbols_by_absolute_location only returns modules at the appropriate offset.
2018-07-19 09:22:57 +01:00
Mike Auty
3ba628da7a
Add in NotAvailableValue for specific uses.
2018-07-18 22:44:27 +01:00
Mike Auty
106a0cb6fd
Rework the array_of_pointers utility function.
...
It now makes use of the original array's symbol table to get the pointer
template, such that the size of the pointer is correct according to the
original table. Resolves "pointer.size" attribute errors (firing inside
a property and thus throwing off unusual exceptions).
2018-07-18 22:35:13 +01:00
Mike Auty
5c41e05876
Improve Module construction.
...
The hash/size determination takes time, so make the hash generated on
use (so far, only on dedupe) and cache it, since it shouldn't change.
We also cache the Module construction, so that if it's done in a loop
(like pslist), it won't keep recaculating for the same module.
2018-07-18 21:46:56 +01:00
Mike Auty
cc5b470602
Remove the caching to see if it's causing the exceptions.
2018-07-18 21:08:50 +01:00
Mike Auty
ce05510413
Additional fixes for module collections.
2018-07-18 14:35:54 +01:00
Mike Auty
91e94440fe
Add in hashing for module differentiation and additional collection features.
2018-07-18 00:42:48 +01:00
Mike Auty
5fbf923186
Fix documentation and try to guess the size where possible.
2018-07-17 21:15:09 +01:00
Mike Auty
8fd1196de7
Fix minor typo.
2018-06-25 00:22:00 +01:00
Mike Auty
9c06c25fae
Add in support for module sizes.
2018-06-25 00:16:17 +01:00
Mike Auty
c012842bd6
Refactor the name to be more accurate.
2018-06-21 00:27:38 +01:00
Mike Auty
aedcf40fc2
Add support for separate symbol_tables and name in Modules.
2018-06-21 00:25:55 +01:00
Mike Auty
ffa54c45eb
Fix linux invalid keyword argument bug.
2018-06-20 22:15:42 +01:00
Mike Auty
70abef1f46
Rework how we handle import errors.
2018-06-19 09:58:09 +01:00
Mike Auty
d9ed86bcc5
Ensure we return the correct values for dir().
2018-06-16 14:29:51 +01:00
Mike Auty
c0ec52822b
Add some typing fixes.
2018-06-16 14:19:36 +01:00
Mike Auty
ac8401991c
Convert all remaining plugins to use the new classmethod pslist.
2018-06-16 13:38:48 +01:00
Mike Auty
86c5302c99
_missing_ was a python-3.6 feature.
2018-06-16 12:36:00 +01:00
Mike Auty
ddeacd3524
Fix up my mistaken advice.
2018-06-16 09:56:10 +01:00
Dave Lassalle and ikelos
a0edd1e38e
root_cell_offset changes seem to have fixed maxaddr problems
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
f2029d5657
add comment about registry key case sensitivity and re-work root_cell_offset
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
b85c143af9
yield UnreadableValues when key not found, and set default RootCell on exception
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
201fc5780a
don't use BaseBlock.Length for maxaddr
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
0c3866ef77
make registry path comparison case insensitive
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
5467c1c5e3
prevent from halting on an unknown registry value type
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
218b1fd37c
use masked length to extract data
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
6cfd3b6499
fix typo in debug statement
2018-06-16 09:54:45 +01:00
Michael Ligh and Mike Auty
76f5d35499
update _KDDEBUGGER_DATA64.get_build_lab() to not reference "nt_symbols"
2018-06-12 08:41:37 +01:00
Michael Ligh and Mike Auty
ae9d7dbc86
use *args and **kwargs when inheriting from IntermediateSymbolTable
2018-06-12 08:41:37 +01:00
Michael Ligh and Mike Auty
fb57e2c5f2
wininfo, procdump, dlldump, and json for pe & kdbg
2018-06-12 08:40:21 +01:00
Mike Auty
2cbd444603
Add in symbol table address masker.
2018-06-06 23:12:46 +01:00
Mike Auty
b228ad8e95
Add comment concerning reconstructability of SymbolTables.
2018-06-06 23:10:21 +01:00
Mike Auty
253304270b
Ensure we can add native_types when we create tables.
2018-06-06 00:42:23 +01:00
Mike Auty
36dee38a9e
Leave pointer out of the default types (since it needs an appropriate size).
2018-06-05 21:46:02 +01:00
Mike Auty
113c23a66d
Last of the typing fix-ups.
2018-06-04 23:55:38 +01:00
Mike Auty
2dc3d2928d
Fix more typing issues.
2018-06-04 23:28:26 +01:00
Dave Lassalle and ikelos
abfcdba524
add Windows 10 Registry process support
2018-06-04 20:17:28 +01:00
Mike Auty
9711793503
Ensure intel.read(pad=True) doesn't return InvalidAddressExceptions.
2018-06-04 09:40:26 +01:00
Mike Auty
f957b2915e
Fix up issue having made optional parameters non-optional.
2018-06-04 09:39:38 +01:00
Mike Auty
7a52ac9deb
Fix a large number of typing issues.
...
There are several instances where mypy didn't detect
if blah is not None:
blah = thing
and so were rewritten as:
blah = blah or thing
2018-06-04 01:25:02 +01:00
Mike Auty
6a6acd2dcc
Move the table_mapping parameter to avoid disrupting the previous interface.
2018-05-30 18:37:29 +01:00
Mike Auty
f72e39d558
Fix up small but significant typo.
...
When asking for data with padding, the padding was guaranteed to always
be at the end without spaces between pages.
2018-05-29 00:42:52 +01:00
Mike Auty
67239002bc
Attempt to fix an intel read issue spotted by imhlv2
...
The length value inside the read method of the TranslationLayer base class
would potentially get overwritten by the inner loop which also defined a
length value.
2018-05-28 23:25:49 +01:00