Module: PWN::Plugins::Volatility
- Defined in:
- lib/pwn/plugins/volatility.rb
Overview
volatility3 wrapper.
Class Method Summary collapse
- .authors ⇒ Object
- .help ⇒ Object
- .required_bins ⇒ Object
- .run(opts = {}) ⇒ Object
- .yara(opts = {}) ⇒ Object
Class Method Details
.authors ⇒ Object
35 36 37 |
# File 'lib/pwn/plugins/volatility.rb', line 35 public_class_method def self. "AUTHOR(S):\n 0day Inc. <[email protected]>\n" end |
.help ⇒ Object
39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 |
# File 'lib/pwn/plugins/volatility.rb', line 39 public_class_method def self.help puts "USAGE: # List host binaries this module expects to be installed. #{self}.required_bins # Run run and return its result #{self}.run( memory: 'required - memory value consumed by #run (defaults to opts[:file])', file: 'optional - filesystem path', plugin: 'required - plugin value consumed by #run (defaults to windows.pslist)' ) # Scan a memory image with a yara rules file. #{self}.yara( rules: 'required - path to a .yar rules file', rule: 'optional - alias for rules', memory: 'required - memory image path', file: 'optional - alias for memory', path: 'optional - alias for memory' ) # Print the AUTHOR(S) string for this module. #{self}.authors " constants.sort end |
.required_bins ⇒ Object
9 10 11 |
# File 'lib/pwn/plugins/volatility.rb', line 9 public_class_method def self.required_bins %w[vol] end |
.run(opts = {}) ⇒ Object
13 14 15 16 17 18 19 20 21 22 23 |
# File 'lib/pwn/plugins/volatility.rb', line 13 public_class_method def self.run(opts = {}) bin = %w[vol volatility3 vol3].find { |b| PWN::Plugins::PreflightChecker.bin?(name: b) } raise PWN::Plugins::PreflightChecker::MissingBinary, 'ERROR: volatility3 (vol) missing' unless bin memory = opts[:memory] || opts[:file] plugin = opts[:plugin] || 'windows.pslist' raise 'ERROR: memory is required' if memory.to_s.empty? stdout, stderr, status = Open3.capture3(bin, '-f', memory.to_s, plugin.to_s) { stdout: stdout, stderr: stderr, exit: status.exitstatus } end |
.yara(opts = {}) ⇒ Object
25 26 27 28 29 30 31 32 33 |
# File 'lib/pwn/plugins/volatility.rb', line 25 public_class_method def self.yara(opts = {}) PWN::Plugins::PreflightChecker.require_bin!(name: 'yara') rules = opts[:rules] || opts[:rule] target = opts[:memory] || opts[:file] || opts[:path] raise 'ERROR: rules and memory/file are required' if rules.to_s.empty? || target.to_s.empty? stdout, stderr, status = Open3.capture3('yara', rules.to_s, target.to_s) { stdout: stdout, stderr: stderr, exit: status.exitstatus } end |