
    [
#gW                          d dl Z d dlmZmZmZ d dlmZmZmZ d dlm	Z	 d dl
mZ d dlmZ d dlmZmZ  e j"                  e      Z edd	efd
efg      Z edd
efg      Z G d dej.                  j0                        Zy)    N)
NamedTupleDict	Generator)
interfaces
exceptions	constants)	renderers)requirements)utility)pslistvadinfoVadData
protectionpathDLLDatac            	       ^   e Zd ZdZdZed        Zdej                  j                  de
eef   fdZdej                  j                  de
eef   fdZdej                  j                  defdZdeed	d	f   fd
Zde
eef   deed	d	f   fdZde
eef   de
eef   deed	d	f   fdZd Zd Zy	)HollowProcesseszLists hollowed processes)      r   c                    t        j                  ddddg      t        j                  dt        dd	      t        j                  d
t
        j                  d      t        j                  dt        j                  d      gS )NkernelzWindows kernelIntel32Intel64)namedescriptionarchitecturespidz9Process IDs to include (all other processes are excluded)T)r   element_typer   optionalr   )r   r   r   )r   	componentversionr   )	r
   ModuleRequirementListRequirementintVersionRequirementr   PsListr   VadInfo)clss    g/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/windows/hollowprocesses.pyget_requirementsz HollowProcesses.get_requirements(   s|     **,()4
 (( W	 ++	 ++'//9
 	
    procreturnc                    i }| j                   j                  | j                  d      }|j                         j	                         D ]  }|j                  t        j                  j                  | j                   |j                  |j                        t        j                        }|j                         }|rt        |t              sd}t        ||      ||j!                         <    |S )a  
        Returns a dictionary of:
            base address -> (protection string, file name)
        For each mapped VAD in the process. This is used
        for quick lookups of data and matching the DLL
        at the same base address as the VAD
        r   z<Non-File Backed Region>)contextmodulesconfigget_vad_roottraverseget_protectionr   r'   protect_values
layer_namesymbol_table_namewinnt_protectionsget_file_name
isinstancestrr   	get_start)selfr,   vadsr   vadprotection_stringfns          r)   _get_vads_datazHollowProcesses._get_vads_data?   s     %%dkk(&;<$$&//1C # 2 2..LL&"3"3V5M5M ))	! ""$BZC0/$+,=r$BD! 2 r+   c                 ,   i }|j                         D ]8  }	 |j                  }	 |j                  j                         }t        |      ||<   : |S # t        j                  $ r Y Rw xY w# t        j                  $ r t        j                         }Y Tw xY w)a  
        Returns a dictionary of:
            base address -> path
        for each DLL loaded in the process

        This is used to cross compare with
        the corresponding VAD and to have a
        backup path source in case of smear
        in the VAD
        )	load_order_modulesDllBaser   InvalidAddressExceptionFullDllName
get_stringr	   UnreadableValuer   )r=   r,   dllsentrybaserG   s         r)   _get_dlls_mapzHollowProcesses._get_dlls_map]   s     ,,.E}}:#//::< !-DJ /  55 
 55 :'779:s"   AA)A&%A&)'BBc                 F   | j                   j                  | j                  d      }	 |j                         }| j                   j	                  |j
                  t        j                  z   dz   ||j                        }|j                  S # t        j                  $ r Y yw xY w)zC
        Uses the PEB to get the image base of the process
        r   _PEB)r6   offsetN)r/   r0   r1   add_process_layerobjectr7   r   BANGPebImageBaseAddressr   rF   )r=   r,   r   proc_layer_namepebs        r)   _get_image_basezHollowProcesses._get_image_base{   s     %%dkk(&;<		"446O,,%%((9>>9FB*xx & C
 '''11 		s   A!B
 
B B Nc              #      K   | j                  |      }|/||j                  k7  rdj                  ||j                         yyyw)aD  
        Detects when the image base in the PEB, which is writable by process malware,
        does not match the section base address - whose value lives in kernel memory.
        Many malware samples will manipulate their image base to fool AVs/EDRs and
        as a necessary part of certain hollowing techniques
        NzhThe ImageBaseAddress reported from the PEB ({:#x}) does not match the process SectionBaseAddress ({:#x}))rX   SectionBaseAddressformat)r=   r,   ___
image_bases        r)   _check_load_addressz#HollowProcesses._check_load_address   sX      ))$/
!jD4K4K&K|  D  DD33  'L!s   AAr>   c              #      K   |j                   }||vrdj                  |       y||   j                  dk7  r0dj                  ||   j                  |||   j                         yyw)a  
        Legitimately mapped application executables and DLLs
        will have a VAD present and its initial protection will be
        PAGE_EXECUTE_WRITECOPY.
        Many process hollowing and code injection techniques will
        unmap the real executable and/or map in executables with
        incorrect permissions.
        This check verifies the VAD for the application exe.
        `_check_dlls_protection` checks for DLLs mapped in the process.
        zNThere is no VAD starting at the base address of the process executable ({:#x})PAGE_EXECUTE_WRITECOPYzVUnexpected protection ({}) for VAD hosting the process executable ({:#x}) with path {}N)rZ   r[   r   r   )r=   r,   r>   r]   rL   s        r)   _check_exe_protectionz%HollowProcesses._check_exe_protection   sw      &&tbii  $Z""&>>jqqT
%%tT$Z__  ?s   A(A*rJ   c              #      K   |D ]I  }||vr||   j                   dk7  sdj                  ||   j                   |||   j                         K y w)Nra   zTUnexpected protection ({}) for DLL in the PEB's load order list ({:#x}) with path {})r   r[   r   )r=   r\   r>   rJ   dll_bases        r)   _check_dlls_protectionz&HollowProcesses._check_dlls_protection   s`      Ht# H~((,DDlssN--xh9L9L  s
   A2Ac              #   t  K   | j                   | j                  | j                  g}|D ]  }| j                  |      }t	        |      dk  r#| j                  |      }t	        |      dk  rCt        j                  |j                        }|j                  }|D ]  } ||||      D ]  }	d|||	ff    y w)N      r   )
r_   rb   re   rM   lenrB   r   array_to_stringImageFileNameUniqueProcessId)
r=   procschecksr,   rJ   r>   	proc_namer   checknotes
             r)   
_generatorzHollowProcesses._generator   s     $$&&''
 D%%d+D4y1}&&t,D4y1}//0B0BCI&&C!$d3D!   4   s   B6B8c                    t         j                  j                  | j                  j	                  dd             }| j
                  j                  | j                  d      }t        j                  dt        fdt        fdt        fg| j                  t         j                  j                  | j
                  |j                  |j                  |                  S )Nr   r   PIDProcessNotes)r/   r6   symbol_tablefilter_func)r   r&   create_pid_filterr1   getr/   r0   r	   TreeGridr$   r;   rr   list_processesr6   r7   )r=   rx   r   s      r)   runzHollowProcesses.run   s    mm55dkkooeT6RS%%dkk(&;<!!C #
 OO,, LL%00!'!9!9 +	 - 
 	
r+   )__name__
__module____qualname____doc___required_framework_versionclassmethodr*   r   objectsObjectInterfacer   r$   r   rB   r   rM   rX   r   r;   r_   rb   re   rr   r}    r+   r)   r   r   #   s   ""+
 
,&&66	c7l	<&&66	c7l	<J$6$6$F$F 3 ")CtO2L sG|,	3d?	#0CL)15c7l1C	3d?	#8
r+   r   )loggingtypingr   r   r   volatility3.frameworkr   r   r   r	   #volatility3.framework.configurationr
   volatility3.framework.objectsr   volatility3.plugins.windowsr   r   	getLoggerr~   vollogr;   r   r   pluginsPluginInterfacer   r   r+   r)   <module>r      s     . . C C + < 1 7			8	$
	s	 	J
j((88 J
r+   