Files
volatility3/volatility/framework/plugins/configwriter.py
T
Mike Auty 35ad2325a8 Move all core plugins over to framework/plugins.
This should have no impact functionality-wise.
The statistics plugin was left out a) as an example and b) because it
was committed by mistake in the first place and was never meant to be a
real plugin.
2018-12-16 13:40:15 +00:00

47 lines
1.9 KiB
Python

import json
import logging
from typing import List
from volatility.framework import renderers, interfaces
from volatility.framework.configuration import requirements
from volatility.framework.interfaces import plugins
vollog = logging.getLogger(__name__)
class ConfigWriter(plugins.PluginInterface):
"""Runs the automagics and both prints and outputs configuration in the output directory"""
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [requirements.TranslationLayerRequirement(name = 'primary',
description = 'Kernel Address Space',
architectures = ["Intel32", "Intel64"]),
requirements.BooleanRequirement(name = 'extra',
description = 'Outputs whole configuration tree',
default = False,
optional = True)
]
def _generator(self):
filename = "config.json"
config = dict(self.build_configuration())
if self.config.get('extra', False):
vollog.debug("Outputting additional information, this will NOT work with the -c option")
config = dict(self.context.config)
filename = "config.extra"
try:
filedata = plugins.FileInterface(filename)
filedata.data.write(bytes(json.dumps(config, sort_keys = True, indent = 2), 'latin-1'))
self.produce_file(filedata)
except Exception:
vollog.warn("Unable to JSON encode configuration")
for k, v in config.items():
yield (0, (k, json.dumps(v)))
def run(self):
return renderers.TreeGrid([("Key", str),
("Value", str)],
self._generator())