Mike Auty
f28ee6077e
Update for the new classmethod model.
2018-06-17 11:16:27 +01:00
Mike Auty
a1caf8d149
Add in initial VAD yarascan code.
2018-06-17 11:16:27 +01:00
Mike Auty
9c2ba66c53
Add in initial version of yarascan plugin.
2018-06-17 11:16:27 +01:00
Mike Auty
c0ec52822b
Add some typing fixes.
2018-06-16 14:19:36 +01:00
Mike Auty
60df83ef15
Convert modules/moddump to classmethod.
2018-06-16 14:03:22 +01:00
Mike Auty
ecb9d5cf05
Convert vadinfo calls to classmethods.
2018-06-16 13:38:48 +01:00
Mike Auty
c4c6d30d42
Rejig where the pslist plugin exists.
2018-06-16 13:38:48 +01:00
Mike Auty
ac8401991c
Convert all remaining plugins to use the new classmethod pslist.
2018-06-16 13:38:48 +01:00
Mike Auty
6ca34e6607
Start converting plugins to use classmethod pslist.
2018-06-16 13:38:48 +01:00
Mike Auty
aea59ffa34
Make the change for the core pslist (breaks lots of plugins).
2018-06-16 13:38:48 +01:00
Dave Lassalle and ikelos
09475d5992
set default value for key since we combined exception handling
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
c68d02d565
combine exception handling to reduce code duplication
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
b85c143af9
yield UnreadableValues when key not found, and set default RootCell on exception
2018-06-16 09:54:45 +01:00
Dave Lassalle and ikelos
481ea01149
catch the KeyError so we can iterate over all hives for a key path
2018-06-16 09:54:45 +01:00
Mike Auty
33e146533e
Fix minor typo in malfind.
2018-06-15 23:04:01 +01:00
Michael Ligh and ikelos
7338cdbf8a
BaseDllName should be an UnreadableValue() if it cannot be accessed
2018-06-13 15:10:58 +01:00
Michael Ligh and ikelos
3eeb48cc0e
add the moddump plugin for windows
2018-06-13 15:10:58 +01:00
Michael Ligh
95214216ea
BaseDllName and FullDllName should be UnreadableValue() if they cannot be accessed
2018-06-13 09:10:47 -05:00
Mike Auty
5f130a3b2a
Update timeliner and convert pslist to support it.
2018-06-12 09:01:01 +01:00
Mike Auty
eed92de9ef
Bulk of the modifications for the timeliner interface.
2018-06-12 09:01:01 +01:00
Michael Ligh and Mike Auty
7ae0d654c2
pass native_types to KdbgIntermedSymbols.create() instead of table_mapping
2018-06-12 08:41:37 +01:00
Michael Ligh and Mike Auty
7797a6a385
add a class string to windows.info so that the plugin has a description
2018-06-12 08:40:21 +01:00
Michael Ligh and Mike Auty
fb57e2c5f2
wininfo, procdump, dlldump, and json for pe & kdbg
2018-06-12 08:40:21 +01:00
Mike Auty
2dc3d2928d
Fix more typing issues.
2018-06-04 23:28:26 +01:00
Mike Auty
816db6b626
Fix up some missing logging names that slipped through the review net.
2018-06-04 10:10:44 +01:00
Mike Auty
d3782c0519
Fix typo as identified by @imhlv2.
2018-06-03 23:51:46 +01:00
Mike Auty
9740c4af84
Add in configwriter plugin, fixes issue #26 .
2018-05-31 11:50:40 +01:00
Michael Ligh
17924a0667
refs #27 use _KLDR_DATA_TABLE_ENTRY on windows if its available
2018-05-30 13:55:20 -05:00
Mike Auty
87d0f97f52
Remove the unnecessary exception and add in a better one.
2018-05-23 19:41:40 +01:00
Mike Auty
689756dc9a
Deal with NULL base blocks in the registry code.
2018-05-20 23:25:20 +01:00
Mike Auty
f8b592c236
Make the config path for plugins dynamic.
2018-05-15 00:11:31 +01:00
Michael Ligh
21b2eb7ecc
malfind is reading chunks, not technically pages, so change PAGE_SIZE to CHUNK_SIZE
2018-05-13 18:49:11 -05:00
Michael Ligh and ikelos
deb81aa1c8
address a few of @ikelos comments in the PR
2018-05-13 23:30:03 +01:00
Michael Ligh and ikelos
a01e4e41b0
commit malfind
2018-05-13 23:30:03 +01:00
Mike Auty
577b6c4b5b
Fix strings not being displayed fully because they featured 'non-word' characters.
2018-05-08 23:59:59 +01:00
Mike Auty
b9fbf272d1
Add support for filename requirements
...
At the moment these are no different than strings, but they allow us to
do things like add URI handlers to file names if no scheme is provided,
and eventually do file existence testing. This also allows the web URI
to allow uploads as a means of passing a file in.
The configuration will only store the filename, because otherwise
someone could add a huge file which would need to be carried around in
the config forever after. Handling file existence errors is up to the
UI after the volatility library returns a "file not found" type
exception.
2018-05-08 23:54:08 +01:00
Mike Auty
38e9c8f50b
Add in initial version of the strings plugin.
2018-05-08 00:57:16 +01:00
Mike Auty
2cb5435911
Change the signature for add_process_layer to match linux.
2018-05-07 17:45:40 +01:00
Mike Auty
84c72c9ffc
Remove the unnecessary Volshell check in timeliner.
...
Given that volshell's plugins are now separate and not stored in the
core plugins list, there is no need to protect against it (and there are
no other "interactive" plugins, which will likely be barred from being
in the core set).
2018-05-06 19:39:07 +01:00
Mike Auty
035bada7b7
Refactor volshell from a plugin to a standalone program.
2018-05-06 18:11:15 +01:00
Mike Auty
38eff91371
Remove vestigal update_configuration methods.
2018-05-06 01:24:40 +01:00
Mike Auty
f25d059d49
Add in file producer/consumer API.
2018-04-14 19:51:49 +01:00
Mike Auty
2e50cde2e7
Fix minor typing issues.
2018-04-11 20:50:11 +01:00
Mike Auty
a55d1c0cab
Add in basic pstree plugin.
2018-04-02 13:44:17 +01:00
Mike Auty
e4d57b639f
Add in basic, extremely crude version of timeliner.
...
(So crude, I heard it say the word 'bum' just a moment ago!) 5;P
2018-03-27 00:33:51 +01:00
Mike Auty
2c196c2d79
Ensure looking up recurse doesn't cause an exception.
2018-03-26 01:15:24 +01:00
Mike Auty
90ffe2de99
Add in basic page statistics plugin (runs much quicker under pypy).
2018-03-24 00:31:44 +00:00
Mike Auty
550a361143
Make __init__ calls more flexible and minor linting.
2018-03-23 15:49:54 +00:00
Dave Lassalle and ikelos
1ae43783aa
create utility function for converting windows timestamps
2018-03-21 18:42:38 +00:00
Michael Ligh and ikelos
205af99a3e
Rev2 after rev1 comments
2018-03-19 22:35:00 +00:00