
    Xf                          d dl Z d dlmZmZmZ d dlmZmZmZm	Z	 d dl
mZ d dlmZ d dlmZ d dlmZ d dlmZmZmZ  e j        e          Z G d	 d
ej        j                  ZdS )    N)IterableList	Generator)	renderers
interfaces
exceptions	constants)requirements)format_hints)intermed)pe)poolscannerdlllistpslistc                   >   e Zd ZdZdZdZed             Zedej	        j
        dededeej        j                 fd	            Ze	 ddej	        j
        dededee         deed
d
f         f
d            Zedej	        j
        dee         defd            Zd Zd Zd
S )ModScanz?Scans for modules present in a particular windows memory image.   r   r      r   r   c           
      $   t          j        ddddg          t          j        dt          j        d          t          j        d	t
          j        d
          t          j        dt          j        d
          t          j	        dddd          gS )NkernelzWindows kernelIntel32Intel64)namedescriptionarchitecturesr   r   )r   	componentversionr   r   r   dumpzExtract listed modulesFT)r   r   defaultoptional)
r
   ModuleRequirementVersionRequirementr   PoolScannerr   PsListr   DllListBooleanRequirement)clss    _/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/windows/modscan.pyget_requirementszModScan.get_requirements   s     *,()4  
 +"k.Ey   +	   +'/9   +4	  
 	
    context
layer_namesymbol_tablereturnc              #      K   t           j                            |dg          }t           j                            ||||          D ]}|\  }}}|V  dS )a  Scans for modules using the poolscanner module and constraints.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols

        Returns:
            A list of Driver objects as found from the `layer_name` layer based on Driver pool signatures
        s   MmLdN)r   r%   builtin_constraintsgenerate_pool_scan)	r)   r-   r.   r/   constraintsresult_constraint
mem_object_headers	            r*   scan_moduleszModScan.scan_modules0   s{      $ "-AA7)
 
 "-@@Z{
 
 	 	F 06,KW		 	r,   Npidsc              #     K   g }t           j                            |pg           }t           j                            ||||          D ]}d}	 |j        }|                                }	|                    |t          j        z   dz   ||j	                  }
|
j
        |v rWnM# t          j        $ r; t                              t          j        d                    |                     Y w xY w|                    |
j
                   |	V  dS )aO  Build a cache of possible virtual layers, in priority starting with
        the primary/kernel layer. Then keep one layer per session by cycling
        through the process list.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            pids: A list of process identifiers to include exclusively or None for no filter

        Returns:
            A list of session layer names
        )r-   r.   r/   filter_funcUnknown_MM_SESSION_SPACE)r.   offsetzSProcess {} does not have a valid Session or a layer could not be constructed for itN)r   r&   create_pid_filterlist_processesUniqueProcessIdadd_process_layerobjectr	   BANGSession	SessionIdr   InvalidAddressExceptionvolloglogLOGLEVEL_VVVformatappend)r)   r-   r.   r/   r:   seen_idsr<   procproc_idproc_layer_namesession_spaces              r*   get_session_layerszModScan.get_session_layersL   sR     * >@m55djbAAM00!%#	 1 
 
 !	" !	"D  G."&"8"8":": !( 9>14GG)< !/ ! ! !*h66 7 5   

*ipp     OOM3444!!!!!C!	" !	"s   AB!!AC+*C+session_layersbase_addressc                 X    |D ]&}|j         |                             |          r|c S 'dS )ag  Given a base address and a list of layer names, find a layer that
        can access the specified address.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            session_layers: A list of session layer names
            base_address: The base address to identify the layers that can access it

        Returns:
            Layer name or None if no layers that contain the base address can be found
        N)layersis_valid)r)   r-   rT   rU   r.   s        r*   find_session_layerzModScan.find_session_layer   sH    * ) 	" 	"J~j)22<@@ "!!!!" tr,   c              #     K   | j         j        | j        d                  }t          |                     | j         |j        |j                            }t          j        	                    | j         | j
        ddt          j                  }|                     | j         |j        |j                  D ]3}	 |j                                        }n# t           j        $ r d}Y nw xY w	 |j                                        }n# t           j        $ r d}Y nw xY wd}| j        d         rg|                     | j         ||j                  }d|j        d	}|r9t*          j                            | j         ||| j        |
          }	d}|	r|	j        }dt5          j        |j        j                  t5          j        |j                  t5          j        |j                  |||ffV  5d S )Nr   windowsr   )class_types Disabledr    z'Cannot find a viable session layer for z#x)r.   zError outputting filer   )r-   modulesconfiglistrS   r.   symbol_table_namer   IntermediateSymbolTablecreateconfig_pathr   r\   r9   BaseDllName
get_stringr   rH   FullDllNamerY   DllBaser   r'   dump_peopenpreferred_filenamer   Hexvolr?   SizeOfImage)
selfr   rT   pe_table_namemodrf   rh   file_outputsession_layer_namefile_handles
             r*   
_generatorzModScan._generator   s6     %dk(&;<##f/1I 
 

 !8??L$*It @ 
 
 $$L&+V-E
 
 )	 )	C!!o88::5 ! ! ! !!!o88::5 ! ! ! ! %K{6" E%)%<%<L.#+& &" YXXX% 
E")/"9"9%	#5 #: # #K #:K" E&1&D  $SW^44 $S[11 $S_55
 
 
 
 
?)	 )	s$   5CC#"C#'DDDc           	          t          j        dt          j        fdt          j        fdt          j        fdt          fdt          fdt          fg|                                           S )NOffsetBaseSizeNamePathzFile output)r   TreeGridr   rm   strrv   )rp   s    r*   runzModScan.run   sb    !<+,)*)*$ OO

 

 
	
r,   )N)__name__
__module____qualname____doc___required_framework_version_versionclassmethodr+   r   r-   ContextInterfacer~   r   objectsObjectInterfacer9   r   intr   rS   rY   rv   r    r,   r*   r   r      sj       II"+H
 
 [
0 #4  	
 
*$4	5   [6  8" 8"#48" 8" 	8"
 3i8" 
3d?	#8" 8" 8" [8"t #4 ! 	   [45 5 5n
 
 
 
 
r,   r   )loggingtypingr   r   r   volatility3.frameworkr   r   r   r	   #volatility3.framework.configurationr
   volatility3.framework.renderersr   volatility3.framework.symbolsr   0volatility3.framework.symbols.windows.extensionsr   volatility3.plugins.windowsr   r   r   	getLoggerr   rI   pluginsPluginInterfacer   r   r,   r*   <module>r      s    , , , , , , , , , , N N N N N N N N N N N N < < < < < < 8 8 8 8 8 8 2 2 2 2 2 2 ? ? ? ? ? ? D D D D D D D D D D		8	$	$S
 S
 S
 S
 S
j 0 S
 S
 S
 S
 S
r,   