Files
volatility3/volatility/framework/symbols/metadata.py
T
Mike Auty 29d41470a4 Mass reformat of typing imports
Relented on the strict import of direct objects/classes for the typing
module only.  Typing module components can be directly imported because
it makes the code really painful to read and write otherwise.

This is still in-line with the python style guide adopted from Google at
http://google.github.io/styleguide/pyguide.html section 2.2.
2018-12-16 13:04:22 +00:00

38 lines
1.2 KiB
Python

from typing import Optional, Tuple
from volatility.framework import interfaces
class WindowsMetadata(interfaces.symbols.MetadataInterface):
"""Class to handle the metadata from a Windows symbol table"""
@property
def pe_version(self) -> Optional[Tuple]:
build = self._json_data.get('pe', {}).get('build', None)
revision = self._json_data.get('pe', {}).get('revision', None)
minor = self._json_data.get('pe', {}).get('minor', None)
major = self._json_data.get('pe', {}).get('major', None)
if revision is None or minor is None or major is None:
return None
if build is None:
return major, minor, revision
return major, minor, revision, build
@property
def pe_version_string(self) -> Optional[str]:
if self.pe_version is None:
return None
return ".".join(self.pe_version)
@property
def pdb_guid(self) -> Optional[str]:
return self._json_data.get('pdb', {}).get('GUID', None)
@property
def pdb_age(self) -> Optional[int]:
return self._json_data.get('pdb', {}).get('age', None)
class LinuxMetadata(interfaces.symbols.MetadataInterface):
"""Class to handle the etadata from a Linux symbol table"""