Package modules :: Package processing :: Module memory :: Class VolatilityManager
[hide private]
[frames] | no frames]

Class VolatilityManager

source code

object --+
         |
        VolatilityManager

Handle several volatility results.

Instance Methods [hide private]
 
__init__(self, memfile, osprofile=None)
x.__init__(...) initializes x; see help(type(x)) for signature
source code
 
get_osprofile(self)
Get the OS profile
source code
 
run(self) source code
 
mask_filter(self, old)
Filter out masked stuff.
source code
 
find_taint(self, res)
Find tainted items.
source code
 
cleanup(self)
Delete the memory dump (if configured to do so).
source code

Inherited from object: __delattr__, __format__, __getattribute__, __hash__, __new__, __reduce__, __reduce_ex__, __repr__, __setattr__, __sizeof__, __str__, __subclasshook__

Class Variables [hide private]
  PLUGINS = ["pslist", "psxview", "callbacks", ["idt", "x86"], "...
Properties [hide private]

Inherited from object: __class__

Method Details [hide private]

__init__(self, memfile, osprofile=None)
(Constructor)

source code 

x.__init__(...) initializes x; see help(type(x)) for signature

Overrides: object.__init__
(inherited documentation)

mask_filter(self, old)

source code 

Filter out masked stuff. Keep tainted stuff.


Class Variable Details [hide private]

PLUGINS

Value:
["pslist", "psxview", "callbacks", ["idt", "x86"], "ssdt", ["gdt", "x8\
6"], "timers", "messagehooks", "getsids", "privs", "malfind", "apihook\
s", "dlllist", "handles", "ldrmodules", "mutantscan", "devicetree", "s\
vcscan", "modscan", "yarascan", ["sockscan", "winxp"], ["netscan", "vi\
sta", "win7"],]