
    *1fO                     r   d dl Z d dlZd dlmZmZmZmZmZ d dlm	Z	m
Z
mZmZmZ d dlmZ d dlmZmZ d dlmZ d dlmZ d dlmZ d d	lmZmZ d d
lmZ  ej<                  e      Z  G d de jB                        Z" G d d      Z# G d de
jH                  jJ                        Z& G d dejN                        Z(y)    N)Dict	GeneratorListOptionalTuple)	constants
interfaces	renderers
exceptionssymbols)requirements)pluginsconfiguration)scanners)format_hints)intermed)
extensionsversions)handlesc                       e Zd ZdZdZdZdZy)PoolTypez^Class to maintain the different possible PoolTypes The values must be
    integer powers of 2.         N)__name__
__module____qualname____doc__PAGEDNONPAGEDFREE     c/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/windows/poolscanner.pyr   r      s     EHDr#   r   c                       e Zd ZdZ	 	 	 	 	 	 	 ddededee   dee   deeee	   ee	   f      deeee	   ee	   f      d	ee	   d
e
deee      ddfdZy)PoolConstraintzMClass to maintain tag/size/index/type information about Pool header
    tags.Ntag	type_nameobject_type	page_typesizeindex	alignmentskip_type_testadditional_structuresreturnc
                     || _         || _        || _        || _        || _        || _        || _        || _        |	| _        y N)	r'   r(   r)   r*   r+   r,   r-   r.   r/   )
selfr'   r(   r)   r*   r+   r,   r-   r.   r/   s
             r$   __init__zPoolConstraint.__init__"   sF     "&"	
",%:"r#   )NNNNr   FN)r   r   r   r   bytesstrr   r   r   intboolr   r4   r"   r#   r$   r&   r&      s     &*(,>B?C#$$59;; ; c]	;
 H%; uXc]HSM9:;; hsmXc]:;<; C=; ;  (S	2; 
;r#   r&   c                   n     e Zd Zdej                  j
                  deeef   de	f fdZ
dede	fdZ xZS )PoolHeaderScannermoduleconstraint_lookupr-   c                 $   t         |           || _        || _        || _        | j                  j                  d      }|j                  d      | _        t        j                  |j                         D cg c]  }| c}      | _        y c c}w )N_POOL_HEADERPoolTag)superr4   _module_constraint_lookup
_alignmentget_typerelative_child_offset_header_offsetr   MultiStringScannerkeys_subscanner)r3   r;   r<   r-   header_typec	__class__s         r$   r4   zPoolHeaderScanner.__init__:   sz     	"3#ll++N;)??	J#66)..011Q1
1s   7	Bdatadata_offsetc              #     K   | j                  ||      D ]  \  }}| j                  j                  d|| j                  z
  d      }| j                  |   }	 |j
                  r|j
                  d   r*| j                  |j                  z  |j
                  d   k  r|j
                  d   r*| j                  |j                  z  |j
                  d   kD  r|j                  d}|j                  t        j                  z  r|j                         rd}n_|j                  t        j                  z  r|j                         rd}n/|j                  t        j                  z  r|j                         rd}|sa|j                   Z|j                   d   r|j"                  |j                   d   k  r|j                   d   r|j"                  |j                   d   kD  r||f  y # t$        j&                  $ r Y w xY ww)Nr>   T)r)   offsetabsoluter   r   F)rI   rA   objectrF   rB   r+   rC   	BlockSizer*   r   r!   is_free_poolr    is_nonpaged_poolr   is_paged_poolr,   	PoolIndexr   InvalidAddressException)r3   rM   rN   rP   patternheader
constraintchecks_passs           r$   __call__zPoolHeaderScanner.__call__K   s    #//kB 0	'OFG\\((* 3 33 ) F
 009J&??.!q) OOf.>.>>*//RSBTT$!q) OOf.>.>>*//RSBTT$ ''3"'K",,x}}<&BUBUBW&*",,x/@/@@ 113&*",,x~~= ..0&*& ##/!''*!++j.>.>q.AA$!''*!++j.>.>q.AA$ v&&a0	'V 55 s\   AH AG&H 8G&H BG&4H 67G&-H /+G&H &G=9H <G==H )r   r   r   r	   contextModuleInterfacer   r5   r&   r7   r4   r]   __classcell__)rL   s   @r$   r:   r:   9   sM    
""22
  ~ 56
 	
"1'U 1' 1'r#   r:   c                   l   e Zd ZdZdZdZedeej                  j                     fd       Zd Ze	 dded	ee   dee   fd
       Zedej$                  j&                  dededee   deeeej,                  j.                  ej,                  j.                  f   ddf   f
d       Ze	 	 ddej$                  j&                  dededee   dedeej8                     deeeej,                  j.                  f   ddf   fd       Zedej$                  j&                  dedefd       Zdej@                  fdZ!y)PoolScannerzA generic pool scanner plugin.r   r   r   )r   r   r   r0   c                     t        j                  ddddg      t        j                  dt        j                  d      gS )	NkernelzWindows kernelIntel32Intel64)namedescriptionarchitecturesr   rc   )rh   pluginversion)r   ModuleRequirementPluginRequirementr   Handles)clss    r$   get_requirementszPoolScanner.get_requirements   sE     **,()4
 **w		
 		
r#   c              #   L  K   | j                   j                  | j                  d      }|j                  }| j	                  |      }| j                  | j                   |j                  ||      D ]  \  }}}|j                  dk(  r=|j                  j                  d|j                  j                  j                  d      }n;|j                  dk(  r	 |j                  j                  }nt+        j,                         }d	|j.                  t1        j2                  |j                  j(                        |j                  j                  |ff  y # t        j                  $ r@ t         j#                  t$        j&                  d|j                  j(                  d       Y 2w xY ww)
Nre   Processstringreplace)
max_lengtherrorsFilezSkipping file at z#xr   )r^   modulesconfigsymbol_table_namebuiltin_constraintsgenerate_pool_scan
layer_namer)   ImageFileNamecastvolcountFileNameStringr   rX   volloglogr   LOGLEVEL_VVVrP   r
   NotApplicableValuer(   r   Hex)r3   re   symbol_tableconstraintsr[   
mem_objectrZ   rh   s           r$   
_generatorzPoolScanner._generator   sz    %%dkk(&;<//..|<.2.E.ELL&++\;/
 	*J
F %%2!//44)77;;AA$ 5 
 ''61%..55D !335 (( $$VZZ%6%67JJ))	 -	 "99 JJ!..+JNN,A,A"+EF s,   CF$E'A'F$AF!F$ F!!F$Nr   tags_filterc                 
   t        d| t        j                  z   dz   dt        j                  t        j
                  z  t        j                  z        t        d| t        j                  z   dz   ddd	t        j                  t        j
                  z  t        j                  z  
      t        d| t        j                  z   dz   ddd	t        j                  t        j
                  z  t        j                  z  
      t        d| t        j                  z   dz   ddd	t        j                  t        j
                  z  t        j                  z  
      t        d| t        j                  z   dz   ddt        j                  t        j
                  z  t        j                  z        t        d| t        j                  z   dz   ddt        j                  t        j
                  z  t        j                  z        t        d| t        j                  z   dz   ddt        j                  t        j
                  z  t        j                  z        t        d| t        j                  z   dz   ddt        j                  t        j
                  z  t        j                  z        t        d| t        j                  z   dz   ddt        j                  t        j
                  z  t        j                  z        t        d| t        j                  z   dz   ddt        j                  t        j
                  z  t        j                  z  dg       t        d!| t        j                  z   dz   ddt        j                  t        j
                  z  t        j                  z        t        d"| t        j                  z   d#z   d$t        j                  t        j
                  z  t        j                  z        t        d%| t        j                  z   d&z   d'd(t        j                  t        j
                  z  t        j                  z        t        d)| t        j                  z   d&z   d'd(t        j                  t        j
                  z  t        j                  z        t        d*| t        j                  z   d+z   d,t        j                  t        j
                  z  t        j                  z  d	-      g}|s|S |D cg c]  }|j                  |v s| c}S c c}w ).a  Get built-in PoolConstraints given a list of pool tags.

        The tags_filter is a list of pool tags, and the associated
        PoolConstraints are  returned. If tags_filter is empty or
        not supplied, then all builtin constraints are returned.

        Args:
            symbol_table: The name of the symbol table to prepend to the types used
            tags_filter: List of tags to return or None to return all

        Returns:
            A list of well-known constructed PoolConstraints that match the provided tags
        s   AtmT_RTL_ATOM_TABLE)   N)r(   r+   r*   s   Pro	_EPROCESSrs   )iX  NT)r(   r)   r+   r.   r*   s   Procs   Thr_ETHREADThreads   Thre)r(   r)   r+   r*   s   Fil_FILE_OBJECTrx   )   Ns   Files   Mut_KMUTANTMutant)@   Ns   Mutas   Dri_DRIVER_OBJECTDriver)   N_DRIVER_EXTENSION)r(   r)   r+   r*   r/   s   Drivs   MmLd_LDR_DATA_TABLE_ENTRY)L   Ns   Sym_OBJECT_SYMBOLIC_LINKSymbolicLink)H   Ns   Symbs   CM10_CMHIVE)i   N)r(   r+   r*   r.   )r&   r   BANGr   r   r    r!   r'   )r   r   builtinsr[   s       r$   r|   zPoolScanner.builtin_constraints   s   ( &7:KK "..8+<+<<x}}L	 &7+E% #"..8+<+<<x}}L &7+E% #"..8+<+<<x}}L &7*D$ #"..8+<+<<x}}L &7*D$ "..8+<+<<x}}L &7.H" "..8+<+<<x}}L &7.H" "..8+<+<<x}}L &7*D$"..8+<+<<x}}L &7*D$"..8+<+<<x}}L &7:JJ$ "..8+<+<<x}}L':&; &7:JJ$ "..8+<+<<x}}L &7:QQ"..8+<+<<x}}L	 &7:QQ*"..8+<+<<x}}L &7:QQ*"..8+<+<<x}}L &7)C "..8+<+<<x}}L#i{
z O-5Wz;9V
WWWs   +T?Tr^   r~   r   c              #   p  K   t         j                  j                  |||      }t         j                  j                  |||      }t	        j
                  ||      }t	        j                  ||      }|}	|s|j                  |	   j                  d   }	t        j                  ||      rd}
nd}
| j                  ||	|||
      D ]  \  }}|j                  ||||      }|D ]  }|2t        j                  t        j                   d|j"                          7|j$                  <|j&                  s0	 |j)                         j+                  ||      |j$                  k7  r~	 |||f   y# t,        j.                  $ r4 t        j                  t        j                   d	|j"                          Y w xY ww)
a  

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            constraints: List of pool constraints used to limit the scan results

        Returns:
            Iterable of tuples, containing the constraint that matched, the object from memory, the object header used to determine the object
        )r^   r~   r   memory_layer      )r-   )r[   use_top_downnative_layer_namekernel_symbol_tableNzCannot create an instance of z$Cannot test instance type check for )r   ro   get_type_mapfind_cookier   is_windows_10is_windows_8_or_laterlayersrz   r   symbol_table_is_64bit	pool_scan
get_objectr   r   r   r   r(   r)   r.   get_object_headerget_object_typer   rX   )rp   r^   r~   r   r   type_mapcookier   r   
scan_layerr-   r[   rZ   mem_objectsr   s                  r$   r}   zPoolScanner.generate_pool_scanL  s    : ??//
 0 
 ,,
 - 
 !..wE ( > >w U  
  
3::>JJ((,?II"%--Z{i #0 #
 "	5J !++%2",$0	 , K * 5
%JJ!..7
8L8L7MN ))5j>W>W!&88:JJ (&  *556
 %6 !*f4415"	56 &== !

%22B:CWCWBXY !!s+   D.F61-E,F6,AF30F62F33F6pool_constraintsr-   progress_callbackc              #   X  K   i }|D ]@  }|j                   |v r!t        dt        |j                                |||j                   <   B | j                  ||      }	|j	                  |	|d      }
|j
                  |   }t        |
||      }|j                  |||      E d{    y7 w)ac  Returns the _POOL_HEADER object (based on the symbol_table template)
        after scanning through layer_name returning all headers that match any
        of the constraints provided.  Only one constraint can be provided per
        tag.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            layer_name: The name of the layer on which to operate
            symbol_table: The name of the table containing the kernel symbols
            pool_constraints: List of pool constraints used to limit the scan results
            alignment: An optional value that all pool headers will be aligned to
            progress_callback: An optional function to provide progress feedback whilst scanning

        Returns:
            An Iterable of pool constraints and the pool headers associated with them
        z5Constraint tag is used for more than one constraint: r   )rP   N)r'   
ValueErrorreprget_pool_header_tabler;   r   r:   scan)rp   r^   r~   r   r   r-   r   r<   r[   pool_header_table_namer;   layerscanners                r$   r   zPoolScanner.pool_scan  s     : :<* 	;J~~!22 KDQ[Q_Q_L`Kab  1;jnn-	; "%!:!:7L!Q 6
1M z*#F,=yI::gw0ABBBs   B B*"B(#B*c           
      L   	 |j                   j                  |t        j                  z   dz          |}|S # t        j
                  $ r t        j                  ||      rt        j                  ||      }|rd}nd}nd}t        j                  ||      }|rt        j                  j                  }nt        j                  j                  }t        j                   j#                  |t%        j&                  |j                   |   j(                  d      d|d|id|i      }Y |S w xY w)	aA  Returns the appropriate symbol_table containing a _POOL_HEADER type, even if the original symbol table
        doesn't contain one.

        Args:
            context: The context that the symbol tables does (or will) reside in
            symbol_table: The expected symbol_table to contain the _POOL_HEADER type
        r>   zpoolheader-x64-win7zpoolheader-x64zpoolheader-x86
poolheaderwindows
nt_symbols)r^   config_pathsub_pathfilenametable_mappingclass_types)symbol_spacerD   r   r   r   SymbolErrorr   r   r   is_windows_7is_vista_or_laterr   poolPOOL_HEADER_VISTAPOOL_HEADERr   IntermediateSymbolTablecreater   	path_joinr   )rp   r^   r   
table_nameis_win_7pool_header_json_filenamer   
class_types           r$   r   z!PoolScanner.get_pool_header_table  s$   !	  ))y~~-> &J< ; %% 	 ,,WlC#00,G0E-0@-,<) !) : :7L Q '__>>
'__88
!99@@)33((6BBL #2+\:+Z8 A 	J ;	s   15 C*D#"D#c                     t        j                  dt        fdt        j                  fdt        fdt        fg| j                               S )NTagOffsetLayerName)r
   TreeGridr6   r   r   r   )r3   s    r$   runzPoolScanner.run  sC    !!S\Hl&6&67'3&RUWOO
 	
r#   r2   )r   N)"r   r   r   r   _version_required_framework_versionclassmethodr   r	   r   RequirementInterfacerq   r   staticmethodr6   r5   r&   r|   r^   ContextInterfacer   r   objectsObjectInterfacer}   r7   r   r   ProgressCallbackr   r   r
   r   r   r"   r#   r$   rb   rb      s   (H"+

j&>&>&S&S!T 

 

$L 6:QXQX(,UQX	n	QX QXf U5##44U5 U5 	U5
 .)U5 
....0	

 		
U5 U5n  BF*C##44*C *C 	*C
 ~.*C *C $I$>$>?*C 
nj00@@@A4M
*C *CX - ((99-IL-	- -^
Y'' 
r#   rb   ))enumloggingtypingr   r   r   r   r   volatility3.frameworkr   r	   r
   r   r   #volatility3.framework.configurationr    volatility3.framework.interfacesr   r   volatility3.framework.layersr   volatility3.framework.renderersr   volatility3.framework.symbolsr   %volatility3.framework.symbols.windowsr   r   volatility3.plugins.windowsr   	getLoggerr   r   IntFlagr   r&   r   ScannerInterfacer:   PluginInterfacerb   r"   r#   r$   <module>r      s   
   9 9 W W < C 1 8 2 F /			8	$t|| ; ;6C'
)):: C'LF
')) F
r#   