
    *1fO                     `   d dl Z d dlZd dlmZmZmZmZmZ d dlm	Z	m
Z
mZmZmZ d dlmZ d dlmZmZ d dlmZ d dlmZ d dlmZ d d	lmZmZ d d
lmZ  ej        e          Z  G d de j!                  Z" G d d          Z# G d de
j$        j%                  Z& G d dej'                  Z(dS )    N)Dict	GeneratorListOptionalTuple)	constants
interfaces	renderers
exceptionssymbols)requirements)pluginsconfiguration)scanners)format_hints)intermed)
extensionsversions)handlesc                       e Zd ZdZdZdZdZdS )PoolTypez^Class to maintain the different possible PoolTypes The values must be
    integer powers of 2.         N)__name__
__module____qualname____doc__PAGEDNONPAGEDFREE     c/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/windows/poolscanner.pyr   r      s)          EHDDDr#   r   c                       e Zd ZdZ	 	 	 	 	 	 	 ddededee         dee         d	eeee	         ee	         f                  d
eeee	         ee	         f                  dee	         de
deee                  ddfdZdS )PoolConstraintzMClass to maintain tag/size/index/type information about Pool header
    tags.Nr   Ftag	type_nameobject_type	page_typesizeindex	alignmentskip_type_testadditional_structuresreturnc
                     || _         || _        || _        || _        || _        || _        || _        || _        |	| _        d S N)	r'   r(   r)   r*   r+   r,   r-   r.   r/   )
selfr'   r(   r)   r*   r+   r,   r-   r.   r/   s
             r$   __init__zPoolConstraint.__init__"   sL     "&"	
",%:"""r#   )NNNNr   FN)r   r   r   r   bytesstrr   r   r   intboolr   r4   r"   r#   r$   r&   r&      s          &*(,>B?C#$$59; ;; ; c]	;
 H%; uXc]HSM9:;; hsmXc]:;<; C=; ;  (S	2; 
; ; ; ; ; ;r#   r&   c                   `     e Zd Zdej        j        deeef         de	f fdZ
dede	fdZ xZS )PoolHeaderScannermoduleconstraint_lookupr-   c                 D   t                                                       || _        || _        || _        | j                            d          }|                    d          | _        t          j	        d |
                                D                       | _        d S )N_POOL_HEADERPoolTagc                     g | ]}|S r"   r"   ).0cs     r$   
<listcomp>z.PoolHeaderScanner.__init__.<locals>.<listcomp>H   s    1111Q111r#   )superr4   _module_constraint_lookup
_alignmentget_typerelative_child_offset_header_offsetr   MultiStringScannerkeys_subscanner)r3   r;   r<   r-   header_type	__class__s        r$   r4   zPoolHeaderScanner.__init__:   s     	"3#l++N;;)??	JJ#611)..00111
 
r#   datadata_offsetc              #   `  K   |                      ||          D ]\  }}| j                            d|| j        z
  d          }| j        |         }	 |j        X|j        d         r| j        |j        z  |j        d         k     rl|j        d         r| j        |j        z  |j        d         k    r|j        d}|j        t          j
        z  r|                                rd}nU|j        t          j        z  r|                                rd}n*|j        t          j        z  r|                                rd}|s%|j        J|j        d         r|j        |j        d         k     rQ|j        d         r|j        |j        d         k    rvn# t$          j        $ r Y w xY w||fV  d S )Nr>   T)r)   offsetabsoluter   r   F)rM   rE   objectrJ   rF   r+   rG   	BlockSizer*   r   r!   is_free_poolr    is_nonpaged_poolr   is_paged_poolr,   	PoolIndexr   InvalidAddressException)r3   rP   rQ   rS   patternheader
constraintchecks_passs           r$   __call__zPoolHeaderScanner.__call__K   s     #//kBB 0	' 0	'OFG\((* 33 )  F
 09J&?.!q) % Of.>>*/RSBTTT$!q) % Of.>>*/RSBTTT$ '3"'K",x}< 	+&BUBUBWBW 	+&*",x/@@+ 1133+ '+",x~=+ ..00+ '+& ! #/!'* %!+j.>q.AAA$!'* %!+j.>q.AAA$5   
 v&&&&&a0	' 0	's+   2F+F1BF>*F*#FF#"F#)r   r   r   r	   contextModuleInterfacer   r5   r&   r7   r4   r`   __classcell__)rO   s   @r$   r:   r:   9   s        
"2
  ~ 56
 	
 
 
 
 
 
"1'U 1' 1' 1' 1' 1' 1' 1' 1' 1'r#   r:   c                   (   e Zd ZdZdZdZedeej	        j
                 fd            Zd Ze	 dded	ee         dee         fd
            Zedej        j        dededee         deeeej        j        ej        j        f         ddf         f
d            Ze	 	 ddej        j        dededee         dedeej                 deeeej        j        f         ddf         fd            Zedej        j        dedefd            Zdej         fdZ!dS )PoolScannerzA generic pool scanner plugin.r   r   r   )r   r   r   r0   c                 v    t          j        ddddg          t          j        dt          j        d          gS )	NkernelzWindows kernelIntel32Intel64)namedescriptionarchitecturesr   rf   )rk   pluginversion)r   ModuleRequirementPluginRequirementr   Handles)clss    r$   get_requirementszPoolScanner.get_requirements   sQ     *,()4  
 *w	  	
 		
r#   c              #     K   | j         j        | j        d                  }|j        }|                     |          }|                     | j         |j        ||          D ]\  }}}|j        dk    r-|j        	                    d|j        j
        j        d          }nt|j        dk    rV	 |j        j        }n[# t          j        $ r6 t                               t$          j        d|j
        j        d           Y w xY wt+          j                    }d	|j        t1          j        |j
        j                  |j
        j        |ffV  d S )
Nrh   Processstringreplace)
max_lengtherrorsFilezSkipping file at z#xr   )ra   modulesconfigsymbol_table_namebuiltin_constraintsgenerate_pool_scan
layer_namer)   ImageFileNamecastvolcountFileNameStringr   r[   volloglogr   LOGLEVEL_VVVrS   r
   NotApplicableValuer(   r   Hex)r3   rh   symbol_tableconstraintsr^   
mem_objectr]   rk   s           r$   
_generatorzPoolScanner._generator   s     %dk(&;</..|<<.2.E.EL&+\;/
 /
 	 	*J
F %22!/44)7;A$ 5  
 '611%.5DD!9   JJ!.FJN,AFFF   H !355 ( $VZ%677J)	    -	 	s   (B55AC:9C:Nr   tags_filterc                    t          d| t          j        z   dz   dt          j        t          j        z  t          j        z            t          d| t          j        z   dz   ddd	t          j        t          j        z  t          j        z  
          t          d| t          j        z   dz   ddd	t          j        t          j        z  t          j        z  
          t          d| t          j        z   dz   ddd	t          j        t          j        z  t          j        z  
          t          d| t          j        z   dz   ddt          j        t          j        z  t          j        z            t          d| t          j        z   dz   ddt          j        t          j        z  t          j        z            t          d| t          j        z   dz   ddt          j        t          j        z  t          j        z            t          d| t          j        z   dz   ddt          j        t          j        z  t          j        z            t          d| t          j        z   dz   ddt          j        t          j        z  t          j        z            t          d| t          j        z   dz   ddt          j        t          j        z  t          j        z  dg           t          d!| t          j        z   dz   ddt          j        t          j        z  t          j        z            t          d"| t          j        z   d#z   d$t          j        t          j        z  t          j        z            t          d%| t          j        z   d&z   d'd(t          j        t          j        z  t          j        z            t          d)| t          j        z   d&z   d'd(t          j        t          j        z  t          j        z            t          d*| t          j        z   d+z   d,t          j        t          j        z  t          j        z  d	-          g}s|S fd.|D             S )/a  Get built-in PoolConstraints given a list of pool tags.

        The tags_filter is a list of pool tags, and the associated
        PoolConstraints are  returned. If tags_filter is empty or
        not supplied, then all builtin constraints are returned.

        Args:
            symbol_table: The name of the symbol table to prepend to the types used
            tags_filter: List of tags to return or None to return all

        Returns:
            A list of well-known constructed PoolConstraints that match the provided tags
        s   AtmT_RTL_ATOM_TABLE)   N)r(   r+   r*   s   Pro	_EPROCESSrv   )iX  NT)r(   r)   r+   r.   r*   s   Procs   Thr_ETHREADThreads   Thre)r(   r)   r+   r*   s   Fil_FILE_OBJECTr{   )   Ns   Files   Mut_KMUTANTMutant)@   Ns   Mutas   Dri_DRIVER_OBJECTDriver)   N_DRIVER_EXTENSION)r(   r)   r+   r*   r/   s   Drivs   MmLd_LDR_DATA_TABLE_ENTRY)L   Ns   Sym_OBJECT_SYMBOLIC_LINKSymbolicLink)H   Ns   Symbs   CM10_CMHIVE)i   N)r(   r+   r*   r.   c                 &    g | ]}|j         v |S r"   )r'   )rA   r^   r   s     r$   rC   z3PoolScanner.builtin_constraints.<locals>.<listcomp>J  s%    WWWz;9V9V
9V9V9Vr#   )r&   r   BANGr   r   r    r!   )r   r   builtinss    ` r$   r   zPoolScanner.builtin_constraints   s   ( &7:KK ".8+<<x}L	   &7+E% #".8+<<x}L   &7+E% #".8+<<x}L   &7*D$ #".8+<<x}L   &7*D$ ".8+<<x}L   &7.H" ".8+<<x}L   &7.H" ".8+<<x}L   &7*D$".8+<<x}L   &7*D$".8+<<x}L   &7:JJ$ ".8+<<x}L':&;   &7:JJ$ ".8+<<x}L   &7:QQ".8+<<x}L	   &7:QQ*".8+<<x}L   &7:QQ*".8+<<x}L   &7)C ".8+<<x}L#  i{
z  	OWWWWXWWWWr#   ra   r   r   c              #   D  K   t           j                            |||          }t           j                            |||          }t	          j        ||          }t	          j        ||          }|}	|s|j        |	         j        d         }	t          j
        ||          rd}
nd}
|                     ||	|||
          D ]\  }}|                    ||||          }|D ]}|.t                              t          j        d|j                    2|j        }|j        sv	 |                                                    ||          |j        k    rsnB# t,          j        $ r0 t                              t          j        d	|j                    Y w xY w|||fV  dS )
a  

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            constraints: List of pool constraints used to limit the scan results

        Returns:
            Iterable of tuples, containing the constraint that matched, the object from memory, the object header used to determine the object
        )ra   r   r   memory_layer      )r-   )r^   use_top_downnative_layer_namekernel_symbol_tableNzCannot create an instance of z$Cannot test instance type check for )r   rr   get_type_mapfind_cookier   is_windows_10is_windows_8_or_laterlayersr}   r   symbol_table_is_64bit	pool_scan
get_objectr   r   r   r   r(   r)   r.   get_object_headerget_object_typer   r[   )rs   ra   r   r   r   type_mapcookier   r   
scan_layerr-   r^   r]   mem_objectsr   s                  r$   r   zPoolScanner.generate_pool_scanL  s,     : ?//
 0 
 
 ,,
 - 
 
 !.wEE ( >w U U  
  	K 
3:>JJ(,?? 	III"%--Z{i #0 #
 #
 "	5 "	5J !++%2",$0	 ,  K * 5 5
%JJ!.N
8LNN   )5j>W5!&88::JJ (&   *56 6
 %6 &= ! ! !

%2Y:CWYY   !! !*f4444415"	5 "	5s   "1E<FFr   pool_constraintsr-   progress_callbackc              #   X  K   i }|D ]9}|j         |v r$t          dt          |j                              |||j         <   :|                     ||          }	|                    |	|d          }
|j        |         }t          |
||          }|                    |||          E d{V  dS )ac  Returns the _POOL_HEADER object (based on the symbol_table template)
        after scanning through layer_name returning all headers that match any
        of the constraints provided.  Only one constraint can be provided per
        tag.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            pool_constraints: List of pool constraints used to limit the scan results
            alignment: An optional value that all pool headers will be aligned to
            progress_callback: An optional function to provide progress feedback whilst scanning

        Returns:
            An Iterable of pool constraints and the pool headers associated with them
        z5Constraint tag is used for more than one constraint: r   )rS   N)r'   
ValueErrorreprget_pool_header_tabler;   r   r:   scan)rs   ra   r   r   r   r-   r   r<   r^   pool_header_table_namer;   layerscanners                r$   r   zPoolScanner.pool_scan  s      : :<* 	; 	;J~!222 bDQ[Q_L`L`bb   1;jn--!$!:!:7L!Q!Q 6
1MM z*#F,=yII::gw0ABBBBBBBBBBBr#   c           
          	 |j                             |t          j        z   dz              |}n# t          j        $ r t          j        ||          rt          j	        ||          }|rd}nd}nd}t          j
        ||          }|rt          j        j        }nt          j        j        }t          j                            |t%          j        |j         |         j        d          d|d|id|i          }Y nw xY w|S )	aA  Returns the appropriate symbol_table containing a _POOL_HEADER type, even if the original symbol table
        doesn't contain one.

        Args:
            context: The context that the symbol tables does (or will) reside in
            symbol_table: The expected symbol_table to contain the _POOL_HEADER type
        r>   zpoolheader-x64-win7zpoolheader-x64zpoolheader-x86
poolheaderwindows
nt_symbols)ra   config_pathsub_pathfilenametable_mappingclass_types)symbol_spacerH   r   r   r   SymbolErrorr   r   r   is_windows_7is_vista_or_laterr   poolPOOL_HEADER_VISTAPOOL_HEADERr   IntermediateSymbolTablecreater   	path_joinr   )rs   ra   r   
table_nameis_win_7pool_header_json_filenamer   
class_types           r$   r   z!PoolScanner.get_pool_header_table  s:   !	 ))y~->   &JJ% 	 	 	 ,WlCC =#0,GG A0E--0@--,<) !) :7L Q Q  9'_>

'_8
!9@@)3(6BL  #2+\:+Z8 A 	 	JJJ'	: s   ,/ C	C;:C;c                     t          j        dt          fdt          j        fdt          fdt          fg|                                           S )NTagOffsetLayerName)r
   TreeGridr6   r   r   r   )r3   s    r$   runzPoolScanner.run  sE    !S\Hl&67'3&RUWOO
 
 	
r#   r2   )r   N)"r   r   r   r   _version_required_framework_versionclassmethodr   r	   r   RequirementInterfacert   r   staticmethodr6   r5   r&   r   ra   ContextInterfacer   r   objectsObjectInterfacer   r7   r   r   ProgressCallbackr   r   r
   r   r   r"   r#   r$   re   re      se       ((H"+

j&>&S!T 

 

 

 [

$ $ $L 6:QX QXQX(,UQX	n	QX QX QX \QXf U5#4U5 U5 	U5
 .)U5 
..0	

 		
U5 U5 U5 [U5n  BF*C *C#4*C *C 	*C
 ~.*C *C $I$>?*C 
nj0@@A4M
*C *C *C [*CX - (9-IL-	- - - [-^
Y' 
 
 
 
 
 
r#   re   ))enumloggingtypingr   r   r   r   r   volatility3.frameworkr   r	   r
   r   r   #volatility3.framework.configurationr    volatility3.framework.interfacesr   r   volatility3.framework.layersr   volatility3.framework.renderersr   volatility3.framework.symbolsr   %volatility3.framework.symbols.windowsr   r   volatility3.plugins.windowsr   	getLoggerr   r   IntFlagr   r&   r   ScannerInterfacer:   PluginInterfacere   r"   r#   r$   <module>r      s  
   9 9 9 9 9 9 9 9 9 9 9 9 9 9 W W W W W W W W W W W W W W < < < < < < C C C C C C C C 1 1 1 1 1 1 8 8 8 8 8 8 2 2 2 2 2 2 F F F F F F F F / / / / / /		8	$	$    t|   ; ; ; ; ; ; ; ;6C' C' C' C' C'
): C' C' C'LF
 F
 F
 F
 F
') F
 F
 F
 F
 F
r#   