Files
volatility3/volatility/framework/objects/utility.py
T
Nick L. Petroni, Jr 5bb2aef9fc Created linux.proc.Maps plugin.
Added object extensions for the key structures. Also added
constants.linux, which will contain Linux-specific constants
that can't be extracted via dwarf.
2017-08-16 16:14:33 -04:00

19 lines
848 B
Python

from volatility.framework import objects
def array_to_string(array, errors = 'replace'):
"""Takes a volatility Array of characters and returns a string"""
# TODO: Consider checking the Array's target is a native char
if not isinstance(array, objects.Array):
raise TypeError("Array_to_string takes an Array of char")
return array.cast("string", max_length = array.vol.count, errors = errors)
def pointer_to_string(pointer, count, errors = 'replace'):
"""Takes a volatility Pointer to characters and returns a string"""
if not isinstance(pointer, objects.Pointer):
raise TypeError("pointer_to_string takes a Pointer")
if count < 1:
raise ValueError("pointer_to_string requires a positive count")
char = pointer.dereference()
return char.cast("string", max_length = count, errors=errors)