
    Xf2                     4   d dl Z d dlZd dlmZmZmZmZmZmZm	Z	m
Z
 d dlmZmZmZmZ d dlmZ d dlmZmZ d dlmZ d dlmZ d dlmZ d d	lmZ  ej        e          Z G d
 dej                   Z! G d dej                   Z" G d dej#                  Z$dS )    N)AnyCallableDictIterableListOptionalTupleUnion)	constants
exceptions
interfacesobjects)requirements)IntRequirementTranslationLayerRequirement)InvalidAddressException)linear)intermed)pslistc                       e Zd ZdZdS )RegistryFormatExceptionzEThrown when an error occurs with the underlying Registry file format.N__name__
__module____qualname____doc__     W/home/panchajanya/Development/work/volatility3/volatility3/framework/layers/registry.pyr   r      s        OOOOr   r   c                       e Zd ZdZdS )RegistryInvalidIndexzAThrown when an index that doesn't exist or can't be found occurs.Nr   r   r   r   r!   r!      s        KKKKr   r!   c                       e Zd Z	 d'dej        j        dededeeee	f                  ddf
 fdZ
d Zdefd	Zedefd
            Zedef fd            Zedefd            ZdeddfdZdeddfdZ	 d(dededeeej                 ej        f         fdZ	 d'deej        gdf         deej                 ddfdZededededefd            Zedeej        j                  fd            Z!dedefdZ"	 d(deded ede#e$eeeeef                  fd!Z%edee         fd"            Z&d)dededefd$Z'edefd%            Z(edefd&            Z) xZ*S )*RegistryHiveNcontextconfig_pathnamemetadatareturnc           
         t                                          ||||           | j        d         | _        | j        d         | _        | j        d         | _        d| _        t          j        	                    || j
        dd          | _        | j                            | j        t          j        z   dz   | j        | j                  }|                                | _        |j        | _        | j        j        d	k    rt+          | j        d
| j         d          t.          j                            | j        | j        d         | j        d                   D ]\}|j                            d|j        j        j        d          }|dk    r(|j        dk    r|                                }|| _         n]| j        j         !                                | _"        d| _#        	 | j        j$        d         j%        | _&        | j        j$        d         j%        | _'        d| j'        z  | _(        tR          *                    t          j+        d| j         dtY          | j(                              d S # tZ          j.        $ rc d| _&        d| _'        d| j'        z  | _(        tR          *                    t          j+        d| j         dtY          | j(                              Y d S w xY w)N)r$   r%   r&   r'   
base_layerhive_offset
nt_symbolsi   windowsregistry_CMHIVEl   >} zRegistry hive at z  does not have a valid signaturestringreplace)
max_lengtherrorsRegistry   r              zSetting hive z max address to zException when setting hive z max address, using )/super__init__config_base_layer_hive_offset_table_name
_page_sizer   IntermediateSymbolTablecreate_config_path_reg_table_namer$   objectr   BANGget_name_cmhive_nameHivehive	Signaturer   r&   r   PsListlist_processesImageFileNamecastvolcountInheritedFromUniqueProcessIdadd_process_layer	BaseBlockdereference_base_block_minaddrStorageLength_hive_maxaddr_non_volatile_hive_maxaddr_volatile_maxaddrvolloglogLOGLEVEL_VVVVhexr   r   )
selfr$   r%   r&   r'   cmhiveproc	proc_nameproc_layer_name	__class__s
            r   r:   zRegistryHive.__init__   s    	4( 	 	
 	
 	
  ;|4 K6;|4!'?FFT&	: 
  
 $$y~-	9
 

 #OO--K	 9*,,)	WD$5WWW   M00L$+l3T[5N
 
 		 		D *//T%7%;%A) 0  I J&&4+LPQ+Q+Q"&"8"8":":#2 9.::<<	.2i.?.B.ID+*.)*;A*>*ED'&)DDDMJJ'O	OO3t};M;MOO     1 	 	 	.8D+*4D'&)DDDMJJ'btybbcRVR_N`N`bb     		s   "B	I- -A.KKc                 "    |r| j         n| j        S N)rZ   rY   )r`   volatiles     r   _get_hive_maxaddrzRegistryHive._get_hive_maxaddrc   s    +3XD''9X	
r   c                     | j         pdS )Nz[NONAME])rG   r`   s    r   rF   zRegistryHive.get_nameh   s     .J.r   c                     | j         S rg   )r=   rk   s    r   r+   zRegistryHive.hive_offsetk   s      r   c                 0    t                      j        dz  S )z9Return a mask that allows for the volatile bit to be set.r7   )r9   address_mask)r`   re   s    r   rn   zRegistryHive.address_masko   s     ww#j00r   c                     t          j        t                    5  | j        j                            ddd          dk    r| j        j        cddd           S 	 ddd           n# 1 swxY w Y   dS )z2Returns the offset for the root cell in this hive.r0   r5   latin-1r2   encodingregfN    )
contextlibsuppressr   rU   rJ   rN   RootCellrk   s    r   root_cell_offsetzRegistryHive.root_cell_offsett   s      !899 	1 	1 *//Y 0    
 '0	1 	1 	1 	1 	1 	1 	1 	1	1 	1 	1 	1 	1 	1 	1 	1 	1 	1 	1 	1 	1 	1 	1 ts   2A&&A*-A*cell_offsetzobjects.StructTypec                 z    | j                             | j        t          j        z   dz   |dz   | j                  }|S )z5Returns the appropriate Cell value for a cell offset.
_CELL_DATAr5   )object_typeoffset
layer_name)_contextrD   r>   r   rE   r&   )r`   ry   cells      r   get_cellzRegistryHive.get_cell   sE     }##(9>9LH?y $ 
 

 r   c                    |                      |          }|                    ddd          }|dk    r|j        j        S |dk    r|j        j        S |dk    r|j        j        S |dk    r|j        j        S |d	k    s|d
k    s|dk    r|j        j        S t          	                    d
                    ||j        j        j        |                     |S )zWReturns the appropriate Node, interpreted from the Cell based on its
        Signature.r0      rp   rq   nkskvkdblflhriz*Unknown Signature {} (0x{:x}) at offset {})r   rN   uKeyNodeKeySecurityKeyValue	ValueDataKeyIndexr\   debugformatrJ   )r`   ry   r   	signatures       r   get_nodezRegistryHive.get_node   s     }}[))IIh1yIII	6>!$6%%$6?"$6##$)t"3"3yD7H7H6?" LL<CCtv~7   
 Kr   Fkeyreturn_listc                 
   |                      | j                  }|j        j                            t
          j        dz             s2t          | j        d	                    |j        j                            |g}|                    d          r
|dd         }|
                    d          }g }|r|r|d                                         }|D ]b}|                                                                |d                                         k    r||gz   }||d         gz   |dd         }} ncg }|r||s<t          d	                    |d         d                    |                              |r|S |d         S )	zGets a specific registry key by key path.

        return_list specifies whether the return result will be a single
        node (default) or a list of nodes from root to the current node
        (if return_list is true).
        _CM_KEY_NODEz&Encountered {} instead of _CM_KEY_NODE\Nr   r6   zKey {} not found under {})r   rx   rO   	type_nameendswithr   rE   r   r&   r   splitget_subkeysrF   lowerKeyErrorjoin)	r`   r   r   	root_nodenode_key	key_array	found_keysubkeyssubkeys	            r   get_keyzRegistryHive.get_key   s    MM$"788	}&//	0OPP 	)	8??M+    ;<< 	crc(CIIdOO	!	 
	H 
	rl..00G!   ??$$**,,	!0B0B0D0DDD'6(2H+4	!~+EyQRQSQS}yIE E
   
	H 
	  	+229Q<9AUAUVV    	O|r   visitornodec                     |s|                      | j                  } ||           |                                D ]}|                     ||           dS )z]Applies a callable (visitor) to all nodes within the registry tree
        from a given node.N)r   rx   r   visit_nodes)r`   r   r   s      r   r   zRegistryHive.visit_nodes   sk      	8==!677D$$&& 	, 	,DWd++++	, 	,r   valuehigh_bitlow_bitc                 <    d|dz   z  dz
  }d|z  dz
  }||z  }| |z  S )zAReturns the bits of a value between highbit and lowbit inclusive.r   r6   r   )r   r   r   	high_masklow_maskmasks         r   _maskzRegistryHive._mask   s9     8a<(A-	wJ!#8#t|r   c                 v    t          dddd          t          j        dd          t          d	d
d          gS )Nr+   z4Offset within the base layer at which the hive livesr   F)r&   descriptiondefaultoptionalr,   zWindows kernel symbols)r&   r   r*   z&Layer in which the registry hive lives)r&   r   r   )r   r   SymbolTableRequirementr   )clss    r   get_requirementszRegistryHive.get_requirements   sf     "R	   /!/G   (!D  
 	
r   r}   c                    |                      |dd          dz	  }|dz  |                     |          k    rt                              t          j        d                    | j        t          |dz            t          |                     |                    |rdnd| 	                                                     t          | j        d          | j        j        |         }|                      |dd          dz	  }|                      |d	d
          d
z	  }|                      |dd          dz	  }|j        j        |         }|j        |         }|                                |z   S )z[Translates a single cell index to a cell memory offset and the
        suboffset within it.   r8   zHLayer {} couldn't translate offset {}, greater than {} in {} store of {}volativeznon-volatilez.Mapping request for value greater than maxaddr               r   )r   ri   r\   r]   r   LOGLEVEL_VVVr   r&   r_   rF   r!   rI   rW   Map	DirectoryTableget_block_offset)	r`   r}   rh   storage	dir_indextable_index	suboffsettableentrys	            r   
_translatezRegistryHive._translate   s]   
 ::fb"--3J!7!7!A!AAAJJ&ZaaI+,,..x8899"*>JJMMOO 	 	 	 '	K   )#H-JJvr2.."4	jjR00B6JJvr1--2	%i0K(%%'')33r   lengthignore_errorsc                 h   |dk     rt          d          g }|}|}| j        || j        dz
  z  z
  }|dk    r{t          ||| j                  }	 |                     |          }|                    ||||| j        f           n# t          j        $ r |s Y nw xY w||z  }||z  }| j        }|dk    {|S )Nr   z7Mapping length of RegistryHive must be positive or zeror6   )
ValueErrorr?   minr   appendr<   r   LayerException)	r`   r}   r   r   responsecurrent_offsetremaining_length
chunk_sizetranslated_offsets	            r   mappingzRegistryHive.mapping  s    A::VWWW
 !_$/A2E(FG
""Z)94?KKJ$(OON$C$C!&")"(    ,   $   j(N
*J% ""& s   4B BBc                     | j         d         gS )z>Returns a list of layer names that this layer translates onto.r*   )r;   rk   s    r   dependencieszRegistryHive.dependencies7  s     L)**r   r6   c                      t          j        t          j                  5  t	           fd                     ||          D                       cddd           S # 1 swxY w Y   dS )z>Returns a boolean based on whether the offset is valid or not.c                 h    g | ].\  }}}}}j         j        |                             ||          /S r   )r$   layersis_valid).0_r}   r   layerr`   s        r   
<listcomp>z)RegistryHive.is_valid.<locals>.<listcomp>A  sM       5Avvu L'.77GG  r   NF)ru   rv   r   r   allr   )r`   r}   r   s   `  r   r   zRegistryHive.is_valid<  s     !CDD 	 	   9=ff9U9U   	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 us   /AA #A c                     | j         S rg   )rV   rk   s    r   minimum_addresszRegistryHive.minimum_addressH  
    }r   c                     | j         S rg   )r[   rk   s    r   maximum_addresszRegistryHive.maximum_addressL  r   r   rg   )F)r6   )+r   r   r   r   r$   ContextInterfacestrr   r   r   r:   ri   rF   propertyintr+   rn   rx   r   r   boolr
   r   r   
StructTyper   r   r   staticmethodr   classmethodconfigurationRequirementInterfacer   r   r   r	   r   r   r   r   r   __classcell__)re   s   @r   r#   r#      s        .2B B#4B B 	B
 4S>*B 
B B B B B BH
 
 

/# / / / / !S ! ! ! X! 1c 1 1 1 1 1 X1 
# 
 
 
 X
C ,@    C ,@    6 -2' ''%)'	tG&');;	<' ' ' 'X .2, ,7-.45, w)*, 
	, , , , S C # #    \ 
j&>&S!T 
 
 
 [
$4 4 4 4 4 4> ?D    #& 7; 	%S#sC/0	1       D +d3i + + + X+
 
s 
C 
 
 
 
 
     X     X    r   r#   )%ru   loggingtypingr   r   r   r   r   r   r	   r
   volatility3.frameworkr   r   r   r   #volatility3.framework.configurationr   0volatility3.framework.configuration.requirementsr   r    volatility3.framework.exceptionsr   volatility3.framework.layersr   volatility3.framework.symbolsr   volatility3.plugins.windowsr   	getLoggerr   r\   r   r   r!   LinearlyMappedLayerr#   r   r   r   <module>r     s        N N N N N N N N N N N N N N N N N N N N L L L L L L L L L L L L < < < < < <        E D D D D D / / / / / / 2 2 2 2 2 2 . . . . . .		8	$	$P P P P Pj7 P P PL L L L L:4 L L Lp p p p p6- p p p p pr   