
    Xf[B                         d dl Z d dlZd dlmZmZmZmZmZ d dlm	Z	m
Z
mZmZmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ  e j        e          Z G d	 d
ej        j                  ZdS )    N)ListIterableTupleOptionalUnion)	constants
exceptions	renderers
interfacessymbols)requirements)format_hints)intermed)versions)ssdtc                      e Zd ZdZdZdZedeej	        j
                 fd            Zedej        j        dededefd	            Zedej        j        d
edededeeeeee         f                  f
d            Zedej        j        d
edededeeeedf                  f
d            Zedej        j        d
edededeeeeee         f                  f
d            Zedej        j        d
edededeeeeee         f                  f
d            Zedej        j        d
edededeeeeef                  f
d            Zedej        j        d
edededeeeeef                  f
d            Zd Zd ZdS )	Callbacksz1Lists kernel callbacks and notification routines.)   r   r      r   r   returnc                 v    t          j        ddddg          t          j        dt          j        d          gS )	NkernelzWindows kernelIntel32Intel64)namedescriptionarchitecturesr   r   )r   pluginversion)r   ModuleRequirementPluginRequirementr   SSDT)clss    a/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/windows/callbacks.pyget_requirementszCallbacks.get_requirements   sQ     *,()4  
 *DIy  	
 		
    contextsymbol_tableconfig_pathc                     | j         |         j        }t          j        | |          }d|i}|rd}nd}t          j                            | |d|||          S )a  Creates a symbol table for a set of callbacks.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            symbol_table: The name of an existing symbol table containing the kernel symbols
            config_path: The configuration path within the context of the symbol table to create

        Returns:
            The name of the constructed callback table
        
nt_symbolszcallbacks-x64zcallbacks-x86windows)native_typestable_mapping)symbol_spacenativesr   symbol_table_is_64bitr   IntermediateSymbolTablecreate)r(   r)   r*   r.   is_64bitr/   symbol_filenames          r%   create_callback_tablezCallbacks.create_callback_table&   sv      +L9A0,GG%|4 	.-OO-O/66%' 7 
 
 	
r'   
layer_namecallback_table_namec              #     K   |j         |         j        d         }|                    |||          }t          j        ||          }|t
          j        z   dz   }g d}	|	D ]\  }
}	 |                    |
          j        }n2# t          j
        $ r  t                              d|
            Y Ow xY w|r|rd}nd}|                    d	||                    d
          |          }|D ]W}	 |                                                    |          }n# t          j        $ r Y <w xY w|j        dk    r|
|j        dfV  XdS )a  Lists all kernel notification routines.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            callback_table_name: The name of the table containing the callback symbols

        Yields:
            A name, location and optional detail string
        kernel_virtual_offsetr8   offset)r(   r)   _GENERIC_CALLBACK))PspLoadImageNotifyRoutineF)PspCreateThreadNotifyRoutineT)PspCreateProcessNotifyRoutineTzCannot find @      array_EX_FAST_REFobject_typer=   subtypecountr   N)layersconfigmoduler   is_vista_or_laterr   BANG
get_symboladdressr	   SymbolErrorvollogdebugobjectget_typedereferencecastInvalidAddressExceptionCallback)r$   r(   r8   r)   r9   kvontkrnlmprM   full_type_namesymbol_namessymbol_nameextended_listsymbol_offsetrI   	fast_refsfast_refcallbacks                    r%   list_notify_routineszCallbacks.list_notify_routinesH   s     ( nZ(/0GH>>,:c>RR$6,
 
 
 -y~=@SS
 
 
 +7 	? 	?&K ( 3 3K @ @ H)   9K99::: ! ]  #$ )).99	 (  I & ? ?'3355::>JJHH!9   H $))%x'8$>>>>?'	? 	?s$   'B,B10B1.'DD('D(Nc              #   @  K   |j         |         j        d         }|                    |||          }|t          j        z   dz   }|                    d          j        }|                    d          j        }	|                    d|	          }
|
dk    rd	S |                    d
||                    d          |
          }|D ]W}	 |	                                
                    |          }n# t          j        $ r Y <w xY w|j        dk    rd|j        d	fV  Xd	S )z]
        Lists all registry callbacks from the old format via the CmpCallBackVector.
        r;   r<   _EX_CALLBACK_ROUTINE_BLOCKCmpCallBackVectorCmpCallBackCountunsigned intrG   r=   r   NrD   rE   rF   CmRegisterCallback)rJ   rK   rL   r   rN   rO   rP   rT   rU   rV   rW   r	   rX   Function)r$   r(   r8   r)   r9   rZ   r[   r\   r`   symbol_count_offsetcallback_countra   rb   rc   s                 r%   _list_registry_callbacks_legacyz)Callbacks._list_registry_callbacks_legacy   sk      nZ(/0GH>>,:c>RR).03OO 	 !++,?@@H&112DEEM!&/B ) 
 
 Q4OO %%n55 	 $ 
 
	 " 	D 	DH#//1166~FF5     A%%*H,=tCCCC	D 	Ds   	'C11DDc              #   :  K   |j         |         j        d         }|                    |||          }|t          j        z   dz   }|                    d          j        }|                    d          j        }	|                    d|	          }
|
dk    rd	S |                    d
|          }|                    |d          D ]U}d	}t          j
        t          j                  5  |j        j        }d	d	d	           n# 1 swxY w Y   d|j        d| fV  Vd	S )zH
        Lists all registry callbacks via the CallbackListHead.
        r;   r<   _CM_CALLBACK_ENTRYCallbackListHeadrh   ri   rj   r   N_LIST_ENTRYLinkCmRegisterCallbackExz
Altitude: )rJ   rK   rL   r   rN   rO   rP   rT   to_list
contextlibsuppressr	   rX   AltitudeStringrl   )r$   r(   r8   r)   r9   rZ   r[   r\   r`   rm   rn   callback_listrc   altitudes                 r%   _list_registry_callbacks_newz&Callbacks._list_registry_callbacks_new   s      nZ(/0GH>>,:c>RR,y~=@TT ++,>??G&112DEEM!&/B ) 
 
 Q4 M-XX%--nfEE 	U 	UHH$Z%GHH 4 4#,34 4 4 4 4 4 4 4 4 4 4 4 4 4 4((*;=T(=T=TTTTTT		U 	Us   'D  D	D	c              #   L  K   |j         |         j        d         }|                    |||          }|                    d          r5|                    d          r |                     ||||          E d{V  dS |                    d          r5|                    d          r |                     ||||          E d{V  dS g d}t                              d           |D ]<}d	}	|                    |          rd
}	t                              d| d|	 d           =dS )a  Lists all registry callbacks.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            callback_table_name: The name of the table containing the callback symbols

        Yields:
            A name, location and optional detail string
        r;   r<   rg   rh   Nrr   )rg   rh   rr   z!Failed to get registry callbacks!zdoes not existexistszsymbol  .)rJ   rK   rL   
has_symbolro   r}   rR   rS   )
r$   r(   r8   r)   r9   rZ   r[   symbols_to_checkr^   symbol_statuss
             r%   list_registry_callbacksz!Callbacks.list_registry_callbacks   s     ( nZ(/0GH>>,:c>RR233 	8K8K9
 9
 	 ::\3F             !344 	9L9L:
 :
 	 77\3F               
 LL<===/ G G 0&&{33 -$,ME{EE]EEEFFFF4r'   c              #   h  K   |j         |         j        d         }|                    |||          }	 |                    d          j        }n0# t
          j        $ r t                              d           Y dS w xY w|t          j
        z   dz   }|                    |||z   |          }	|	j        D ]~}
|j         |                             |
j        d          s)	 |                    d	d
|
j        dd          }n(# t
          j        $ r t#          j                    }Y nw xY wd|
j        |fV  dS )a  Lists all kernel bugcheck reason callbacks.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            callback_table_name: The name of the table containing the callback symbols

        Yields:
            A name, location and optional detail string
        r;   r<    KeBugCheckReasonCallbackListHeadz,Cannot find KeBugCheckReasonCallbackListHeadN!_KBUGCHECK_REASON_CALLBACK_RECORD)rG   r=   r8   rB   stringTreplace)absoluter=   
max_lengtherrorsrJ   rK   rL   rO   rP   r	   rQ   rR   rS   r   rN   rT   Entryis_validCallbackRoutine	ComponentrX   r
   UnreadableValuer$   r(   r8   r)   r9   rZ   r[   list_offsetr\   callback_recordrc   	components               r%   list_bugcheck_reason_callbacksz(Callbacks.list_bugcheck_reason_callbacks  s     ( nZ(/0GH>>,:c>RR	"--2  K % 	 	 	LLGHHH44	
  ).03VV 	 "..&s[/@Z ) 
 
 (- 	Z 	ZH>*-66x7OQSTT 8 OO!#-!$ $   	 5 8 8 8%577			8 5h6NPYYYYYY%	Z 	Zs#   A )A<;A<C=="D"!D"c              #     K   |j         |         j        d         }|                    |||          }	 |                    d          j        }n0# t
          j        $ r t                              d           Y dS w xY w|t          j
        z   dz   }|                    |||z   |          }	|	j        D ]}
|j         |                             |
j        d          s)	 |                    |t          j
        z   d	z   ||
j        dd
          }n(# t
          j        $ r t#          j                    }Y nw xY wd|
j        |fV  dS )a  Lists all kernel bugcheck callbacks.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            callback_table_name: The name of the table containing the callback symbols

        Yields:
            A name, location and optional detail string
        r;   r<   KeBugCheckCallbackListHeadz&Cannot find KeBugCheckCallbackListHeadN_KBUGCHECK_CALLBACK_RECORD)r=   r8   rB   r   r   )r8   r=   r   r   r   r   s               r%   list_bugcheck_callbacksz!Callbacks.list_bugcheck_callbacks?  s     ( nZ(/0GH>>,:c>RR	"--.JKKSKK% 	 	 	LLABBB44	
  ).03OO 	 "..3#4 ) 
 
 (- 	T 	TH>*-66x7OQSTT 	8#NN 9>1H<)#-!$ +  		 5 8 8 8%577			8 /0H)SSSSS	T 	Ts#   A )A<;A</D"D21D2c              #   x  K   | j         j        | j        d                  }|                     | j         |j        | j                  }t          j                            | j         |j	        |j                  }| j
        | j        | j        | j        f}|D ]&} || j         |j	        |j        |          D ]\  }}}|t          j                    }	n|}	t!          |                    |                    }
|
r|
D ]~\  }}d}|D ]D}d}d|t%          j        |          ||                    t*          j                  d         |	ffV  E|s.d|t%          j        |          |t          j                    |	ffV  d|t%          j        |          t          j                    t          j                    |	ffV  (d S )Nr   FTr   r   )r(   modulesrK   r7   symbol_table_namer*   r   r#   build_module_collectionr8   rd   r   r   r   r
   NotApplicableValuelist'get_module_symbols_by_absolute_locationr   Hexsplitr   rN   NotAvailableValue)selfr   r9   
collectioncallback_methodscallback_methodcallback_typecallback_addresscallback_detaildetailmodule_symbolsmodule_namesymbol_generatorsymbols_foundsymbols                  r%   
_generatorzCallbacks._generatort  sM     %dk(&;<"88L&2D4D
 
 Y66L&+V-E
 


 %(/(	
  0 9	 9	ODSO!(#	E E 8 8@/ #*&9;;FF,F!%FFGWXX" " " )9G  5%5(- '7  F,0M !$1$0$45E$F$F$/$*LL$@$@$C$*!"	# 	 	 	 	  - 
 !$1$0$45E$F$F$/$-$?$A$A$*!"	# 	 	 	'@ )(,-=>>%799%799"	 	 	 	 	_89	 9	r'   c                     t          j        dt          fdt          j        fdt          fdt          fdt          fg|                                           S )NTyperY   ModuleSymbolDetail)r
   TreeGridstrr   r   r   )r   s    r%   runzCallbacks.run  sR    !\-.333 OO	
 	
 		
r'   )__name__
__module____qualname____doc___required_framework_version_versionclassmethodr   r   configurationRequirementInterfacer&   staticmethodr(   ContextInterfacer   r7   r   r   intr   rd   ro   r}   r   r   r   r   r    r'   r%   r   r      s_       ;;"+H

j&>&S!T 

 

 

 [

 
#4

 
 
	
 
 
 \
B ;?#4;? ;? 	;?
 !;? 
%S(3-/0	1;? ;? ;? [;?z )D#4)D )D 	)D
 !)D 
%S$'	()D )D )D [)DV U#4U U 	U
 !U 
%S(3-/0	1U U U [U@ /#4/ / 	/
 !/ 
%S(3-/0	1/ / / [/b 7Z#47Z 7Z 	7Z
 !7Z 
%S#&	'7Z 7Z 7Z [7Zr 2T#42T 2T 	2T
 !2T 
%S#&	'2T 2T 2T [2ThK K KZ

 

 

 

 

r'   r   )loggingrw   typingr   r   r   r   r   volatility3.frameworkr   r	   r
   r   r   #volatility3.framework.configurationr   volatility3.framework.renderersr   volatility3.framework.symbolsr   %volatility3.framework.symbols.windowsr   volatility3.plugins.windowsr   	getLoggerr   rR   pluginsPluginInterfacer   r   r'   r%   <module>r      s   
      9 9 9 9 9 9 9 9 9 9 9 9 9 9 W W W W W W W W W W W W W W < < < < < < 8 8 8 8 8 8 2 2 2 2 2 2 : : : : : : , , , , , ,		8	$	$x
 x
 x
 x
 x

"2 x
 x
 x
 x
 x
r'   