Files
volatility3/volatility/framework/contexts/__init__.py
T

114 lines
4.8 KiB
Python

"""A `Context` maintains the accumulated state required for various plugins and framework functions.
This has been made an object to allow quick swapping and changing of contexts, to allow a plugin
to act on multiple different contexts without them interfering eith each other.
"""
from volatility.framework import constants, interfaces, symbols
from volatility.framework.interfaces.configuration import HierarchicalDict
__author__ = 'mike'
class Context(interfaces.context.ContextInterface):
"""Maintains the context within which to construct objects
The context object is the main method of carrying around state that's been constructed for the purposes of
investigating memory. It contains a symbol_space of all the symbols that can be accessed by plugins using the
context. It also contains the memory made up of data and translation layers, and it contains a factory method
for creating new objects.
Other context objects can be constructed as long as they support the
:class:`~volatility.framework.interfaces.context.ContextInterface`. This is the primary context object to be used
in the volatility framework. It maintains the
"""
def __init__(self):
"""Initializes the context.
This initializes the context and provides a default set of native types for the empty symbol space.
:param natives: Defines the native types such as integers, floats, arrays and addresses.
:type natives: interfaces.symbols.NativeTableInterface
"""
super().__init__()
self._symbol_space = symbols.SymbolSpace()
self._memory = interfaces.layers.Memory()
self._config = HierarchicalDict()
# ## Symbol Space Functions
@property
def config(self):
"""Returns a mutable copy of the configuration, but does not allow the whole configuration to be altered"""
return self._config
@config.setter
def config(self, value):
if not isinstance(value, HierarchicalDict):
raise TypeError("Config must be of type HierarchicalDict")
self._config = value
@property
def symbol_space(self):
"""The space of all symbols that can be accessed within this context.
"""
return self._symbol_space
@property
def memory(self):
"""A Memory object, allowing access to all data and translation layers currently available within the context"""
return self._memory
# ## Address Space Functions
def add_layer(self, layer):
"""Adds a named translation layer to the context
:param layer: The layer to be added to the memory
:type layer: volatility.framework.interfaces.layers.DataLayerInterface
:raises volatility.framework.exceptions.LayerException: if the layer is already present, or has
unmet dependencies
"""
self._memory.add_layer(layer)
# ## Object Factory Functions
def object(self, symbol, layer_name, offset, **arguments):
"""Object factory, takes a context, symbol, offset and optional layername
Looks up the layername in the context, finds the object template based on the symbol,
and constructs an object using the object template on the layer at the offset.
:param symbol: The name of the symbol type on which to construct the object. This should contain an explicit table name.
:type symbol: str
:param layer_name: The name of the layer on which to construct the object
:type layer_name: str
:param offset: The offset within the layer at which the data used to create the object lives
:type offset: int
:return: A fully constructed object
:rtype: :py:class:`volatility.framework.interfaces.objects.ObjectInterface`
"""
object_template = self._symbol_space.get_type(symbol)
object_template = object_template.clone()
object_template.update_vol(**arguments)
return object_template(context = self,
object_info = interfaces.objects.ObjectInformation(layer_name = layer_name,
offset = offset))
def object_factory(self, symbol_table):
"""Allow a specific symbol_table to be used repeatedly for constructing objects
:param symbol_table: The name of the symbol table that the object factory will construct objects on
:type sybmol_table: str
:return: A function that takes the same arguments as :func:`object`
"""
def callable(symbol, layer_name, offset, **arguments):
"""Function to apply a specific symbol_table name to any unadored"""
if constants.BANG not in symbol:
symbol = symbol_table + constants.BANG + symbol
return self.object(symbol, layer_name, offset, **arguments)
return callable