Andrew Case and ikelos
c0581eeeea
newest updates
2018-12-19 00:54:51 +00:00
Mike Auty
5375e154d8
Add in configuration caching to potentially avoid an unnecessary lookup.
2018-12-17 22:17:02 +00:00
Mike Auty
7ca5514b83
Remove long-broken convenience code from ConfigurableInterface.
...
In the dim and distant past, I seemingly thought it a good idea to copy
all the values out of an object's config and into local private
attributes (I guess to avoid config lookups?). It turns out, it was
always broken because it looking at the root of the config tree, rather
than under the object's specific config settings.
This first turned up as an issue where self._meta_layer was being
overwritten by None in the vmware layer. Removing this resolved the
issue.
2018-12-17 22:08:24 +00:00
Mike Auty
cf94012956
Yapf reformat the poolscanner code.
2018-12-17 19:41:27 +00:00
Michael Ligh and ikelos
90b7f2aa3b
add backup methods of detecting windows versions, in case metadata in the json isn't available
2018-12-17 19:40:14 +00:00
Mike Auty
7f973f9e3e
Refactor the ResourceAccessor so it can be used by layers.
2018-12-17 19:38:18 +00:00
Mike Auty
0462c98f44
Fix up vmss/vmsn typo.
2018-12-17 18:10:17 +00:00
Mike Auty
de4fa6df51
Ensure we can see how the stacker is acting.
2018-12-17 17:32:46 +00:00
Mike Auty
e65a00894a
Minor style tweaks and mass changes across the codebase because of it.
2018-12-17 12:46:14 +00:00
Mike Auty
76e81eb478
Fix up python-3.5 type syntax.
2018-12-17 09:09:34 +00:00
Mike Auty
b61ac3bd47
Many more typing fixes.
2018-12-17 01:17:06 +00:00
Mike Auty
3386b3c536
Minor timeliner fix.
2018-12-16 21:28:30 +00:00
Mike Auty
19572b6e1e
Reformat all python files using yapf with custom volatility style.
2018-12-16 16:50:17 +00:00
Mike Auty
9b951d5fbe
More typing additions and fixes.
2018-12-16 15:21:41 +00:00
Mike Auty
7818fba4a4
Fix up ChainMap issue in python-3.5.
2018-12-16 13:46:04 +00:00
Mike Auty
35ad2325a8
Move all core plugins over to framework/plugins.
...
This should have no impact functionality-wise.
The statistics plugin was left out a) as an example and b) because it
was committed by mistake in the first place and was never meant to be a
real plugin.
2018-12-16 13:40:15 +00:00
Mike Auty
9824538bd9
Numerous pycharm warnings resolved
...
This includes:
* Better ways of checking empty lists
* Not shadowing builtin functions like filter
* Preventing invalid slash warnings by marking strings as regexps
* Removing unnecessary brackets
* Lowercase variable names
* Adding/updating parameters in docstrings
* Removing unused code (lines not chunks)
* Change in not a member tests
* Changing some methods to static
* Shorting range membership checks
* Missing parameters
* Make some exception handlers more specific
* Don't define a lambda to a variable
* A few more instance checks to help type checkers
2018-12-16 13:21:06 +00:00
Mike Auty
29d41470a4
Mass reformat of typing imports
...
Relented on the strict import of direct objects/classes for the typing
module only. Typing module components can be directly imported because
it makes the code really painful to read and write otherwise.
This is still in-line with the python style guide adopted from Google at
http://google.github.io/styleguide/pyguide.html section 2.2.
2018-12-16 13:04:22 +00:00
Mike Auty
0abaa3af2f
Don't load all symbols when we ask to import symbols.
2018-12-14 00:27:46 +00:00
Mike Auty
7502ef7366
Shuffle around registry extensions.
2018-12-14 00:18:57 +00:00
Mike Auty
dfe2f86fe2
Lots and lots of typing additions found by an initial monkeytype run.
2018-12-13 23:46:37 +00:00
Mike Auty
2c72439334
Add in protections for the crashdump layer.
2018-12-13 22:59:21 +00:00
Mike Auty
d9369001d4
Ensure we can cache the linux/mac banners.
2018-12-13 21:23:59 +00:00
Mike Auty
f41e3e0453
Completely rework the primitive data format system.
2018-12-13 18:33:42 +00:00
Mike Auty
6b480eed56
Fix up PE data construction code.
2018-12-13 18:33:42 +00:00
Mike Auty
9949809198
Fix a minor typo.
2018-12-13 18:33:42 +00:00
Mike Auty
b533d19f83
Refactor the data extraction for primitive types.
2018-12-13 18:33:42 +00:00
Mike Auty
a78452e361
Fix up ugly int128 hack with a slightly nicer hack.
2018-12-13 15:56:24 +00:00
Mike Auty
6e43d0bab4
Bring the aslr_mask_symbol_table methods in sync (even though mac never uses it).
2018-12-13 15:56:24 +00:00
Mike Auty
1341925160
Remove unnecessary requirements method.
2018-12-13 15:56:24 +00:00
Mike Auty
cd7296d64e
Fix up based on the recent master refactoring.
2018-12-13 15:56:24 +00:00
Mike Auty
3a2c2b30a9
Use the virtual_to_physical_address in case of extremely large physical files where the masking might break things.
2018-12-13 15:56:24 +00:00
Mike Auty
25fb05c9bf
Fix up Mac double-DTB finding code by address masking the BootPML4 symbol address.
2018-12-13 15:56:24 +00:00
Mike Auty
57b2a5bab7
Fix up a rogue classmethod, and ensure we have a separate variable for the new layer.
2018-12-13 15:56:24 +00:00
Mike Auty
5135215c62
Do some tidying and renaming.
2018-12-13 15:56:24 +00:00
Mike Auty
7a462d5f85
Refactor out the shared symbol cache/finder code from linux and mac.
2018-12-13 15:56:24 +00:00
Mike Auty
55286f04cb
Consolidate identical code into a single symbol cache, add mac automagic list and pycharm reformat.
2018-12-13 15:56:24 +00:00
Andrew Case and ikelos
622c86f9ed
Add initial mac backend code, with broken DTB finding, along with the pslist plugin
2018-12-13 15:56:24 +00:00
Mike Auty
c9a08603c7
Move the get_requirements over to the IntermedSymbols which actually requires the parameter.
2018-12-13 01:39:26 +00:00
Mike Auty
5e8ba16709
Remove the unimplemented hook.
2018-12-13 01:16:05 +00:00
Mike Auty
dfaaf1e455
Fix up some things missed in the master refactor.
2018-12-13 01:16:05 +00:00
Mike Auty
7c4cb0d291
Remove attempts to improve speed that may not help.
2018-12-13 01:16:05 +00:00
Mike Auty
da2f3b38d3
Add in page-table repetition blocking code (helps with windows 10 virtual space).
2018-12-13 01:16:05 +00:00
Michael Ligh and ikelos
736a1c6e50
add is_valid() for _FILE_OBJECT and _EPROCESS
2018-12-13 01:16:05 +00:00
Mike Auty
91b2c61803
Try to add some optimizations to intel scanning.
2018-12-13 01:16:05 +00:00
Mike Auty
76264cee34
Catch invalid _OBJECT_HEADER objects.
2018-12-13 01:16:05 +00:00
Michael Ligh and ikelos
650a188d51
updates for win8/win10 poolscanning
2018-12-13 01:16:05 +00:00
Mike Auty
fa033b8ab7
Back out the symbol_table_name parameter, and provide full symbol names in the constraints.
2018-12-13 01:16:05 +00:00
Mike Auty
eacc45dab6
Ensure POOL_HEADER finds the right object in the right symbol table.
2018-12-13 01:16:05 +00:00
Michael Ligh and ikelos
d653839359
switch Handles.find_cookie() to a classmethod so it can be called from the poolscanner. add typing
2018-12-13 01:16:05 +00:00