Mike Auty
e3e1c4e00b
Initial commit of pyinstaller spec. Some changes to path handling to help.
2018-10-30 23:56:34 +00:00
Mike Auty
f76aa66805
Reduce the risk of scanning the entire virtual address space, given we've already found potential kernels.
2018-10-26 22:39:36 +01:00
Mike Auty
e9bad27793
Add in kdbg_offset method for pdbscan, and make the module_offset the third choice.
2018-10-26 22:28:09 +01:00
Mike Auty
68a4bbf26c
Modularize pdb finding code.
2018-10-26 00:47:01 +01:00
Mike Auty
d799d4edd8
Add additional typing information.
2018-10-11 16:41:59 +01:00
Mike Auty
f1c5b3ca29
Improve the typing in places.
2018-10-11 11:14:29 +01:00
Mike Auty
d829028a36
Apply various type annotation/bug fixes.
2018-10-05 00:16:42 +01:00
Mike Auty
701c56558b
Fix a typo from the big refactor in commit 190ffaf2.
2018-09-28 12:51:55 +01:00
Mike Auty
de3bfad135
Replace 'raise StopIteration' with a blank 'return', since changes in python-3.7 change StopIeration to a RuntimeError.
2018-09-28 12:44:19 +01:00
Mike Auty
00a118a06a
Reduce return results from find_requirements.
2018-09-23 22:24:44 +01:00
Mike Auty
e203d11e0b
Ensure the swap list configuration gets set appropriately.
2018-09-23 13:06:48 +01:00
Mike Auty
190ffaf28b
Refactor where certain types of requirement live (given they're more concrete than interface).
2018-09-20 16:14:57 +01:00
Mike Auty
dd5edc395a
Add in commented code for keeping the zip file in sync if we decide it's needed.
2018-09-03 22:14:48 +01:00
Mike Auty
abee0f8de7
Change the ASLR finding code to return no shift values (and log when it's found none).
2018-09-03 21:48:16 +01:00
Mike Auty
f584be8d18
Fix up the linux symbol caching code.
2018-09-03 21:39:48 +01:00
Mike Auty
0c46da22c3
Readd the check to ensure we don't stack on top of an existing Intel layer.
2018-09-02 19:03:39 +01:00
Mike Auty
7f966901cf
Ensure the dtb can't get specified from an earlier run around the loop.
2018-09-02 18:28:59 +01:00
Mike Auty
c1dc36a327
Fix up the breakage from the preivous commit.
2018-09-02 18:27:28 +01:00
Mike Auty
29f1a0f216
Change the default state for stacking to ensure layer isn't set unless successful.
2018-09-02 17:42:55 +01:00
Mike Auty
5791cfaab7
Stop overriding the builtin filter method, and ensure suitable parameter names.
2018-08-30 11:41:19 +01:00
Mike Auty
3a6b4ad35c
Add in the has_member method for objects and templates.
2018-08-29 22:54:56 +01:00
Mike Auty
b1d46f843b
Convert documentation to napoleon/Google format docstrings.
2018-08-05 15:52:12 +01:00
Mike Auty
eb08fb9e96
Convert the pdb scanner to use the kernel module names constants.
2018-08-04 12:34:18 +01:00
Mike Auty
b6b4c44300
Ensure cross-platform support for linux_cache.
2018-07-22 11:55:10 +01:00
Mike Auty
ffa54c45eb
Fix linux invalid keyword argument bug.
2018-06-20 22:15:42 +01:00
Mike Auty
113c23a66d
Last of the typing fix-ups.
2018-06-04 23:55:38 +01:00
Mike Auty
a07691b04f
Ensure scanners don't return duplicates in the overlap.
2018-05-13 20:55:54 +01:00
Mike Auty
b9fbf272d1
Add support for filename requirements
...
At the moment these are no different than strings, but they allow us to
do things like add URI handlers to file names if no scheme is provided,
and eventually do file existence testing. This also allows the web URI
to allow uploads as a means of passing a file in.
The configuration will only store the filename, because otherwise
someone could add a huge file which would need to be carried around in
the config forever after. Handling file existence errors is up to the
UI after the volatility library returns a "file not found" type
exception.
2018-05-08 23:54:08 +01:00
Mike Auty
4dbfdcc9dd
Fix up typing and metadata usage.
2018-05-01 21:21:12 +01:00
Mike Auty
9512cbe9eb
Commit metadata changeset.
...
Layers now accept metadata dictionaries (and chain/stack them on top of
those from lower layers). Metadata can only be set at construction
time, and the metadata dictionary is readonly. The hope is this will
make enumerating metadata keys across the codebase simpler.
The current metadata items that layers hold is:
architecture (Unknown | Intel32 | Intel64)
os (Unknown | Windows | Linux)
pae (bool)
page_map_offset (int)
This patchset may develop further to help enumerate all of these
(through a registration/reporting system).
2018-04-26 12:48:14 +01:00
Mike Auty
623180ddbd
Make many typing fixes, based on mypy-0.590.
2018-04-22 20:45:59 +01:00
Mike Auty
2e50cde2e7
Fix minor typing issues.
2018-04-11 20:50:11 +01:00
Mike Auty
5938254c3c
Add caching to the stack automagic in case it's reused.
2018-04-02 02:13:59 +01:00
Mike Auty
19236199b1
Refactor stacking and move the automagic location to a constant.
2018-04-02 02:09:56 +01:00
Mike Auty
154732126d
Refactor the automagic choosing code.
2018-03-25 18:15:43 +01:00
Mike Auty
c6a58ffc06
Fix up sphinx warnings.
2018-03-20 22:30:05 +00:00
Mike Auty
98624203c4
Add in windows swap-file automagic.
2018-02-11 18:35:40 +00:00
Mike Auty
f3b6b5311f
Fix up a couple extra typing issues, improving code quality.
2018-02-10 22:51:56 +00:00
Mike Auty
970cfc3cd8
Fix up pdbscan to avoid running if not needed.
2018-02-10 22:44:44 +00:00
Mike Auty
24be045266
Minor fix ups with typing and exceptions.
2018-02-10 22:42:31 +00:00
Mike Auty
5a85f88636
Improve construction automagic (it now continues recursing after errors).
2018-02-10 22:38:50 +00:00
Mike Auty
152dc9a210
Error check for when we can't find the file_symbol_url.
2018-02-07 19:56:02 +00:00
Mike Auty
e362c50460
Ensure we don't run through signatures when we've found one that gives a layer.
2017-12-13 20:48:52 +00:00
Mike Auty
265182b66b
Fix bug that massively broken the wintelstacker, slowing everything else down.
2017-12-13 20:48:52 +00:00
Mike Auty
e23bb65162
Add in better logging.
2017-12-13 20:48:52 +00:00
Mike Auty
f40fae197d
Convert to python3.5 syntax (no local type-annotations).
2017-12-13 20:48:52 +00:00
Mike Auty
6c52e04489
Fix up exception in DTBtests.
...
The exception was being caused by reading too little data from the
stream. We now skip it if that happens.
2017-12-13 20:48:52 +00:00
Mike Auty
de3b8cf76b
Fix exception being thrown in the middle of Nlpdtbfinder for layers without validity details.
2017-12-13 20:48:52 +00:00
Mike Auty
50b60c0df6
Add in more interfaces (and fix additional errors now that type information is available).
2017-12-13 20:48:52 +00:00
Mike Auty
2cc456e847
Finish off the automagic directory type annotations.
2017-12-13 20:48:52 +00:00