Package modules :: Package processing :: Package platform :: Module windows :: Class BehaviorReconstructor
[hide private]
[frames] | no frames]

Class BehaviorReconstructor

source code

object --+
         |
        BehaviorReconstructor

Reconstructs the behavior of behavioral API logs.

Instance Methods [hide private]
 
__init__(self)
x.__init__(...) initializes x; see help(type(x)) for signature
source code
 
process_apicall(self, event) source code
 
_api_CreateDirectoryW(self, return_value, arguments, flags) source code
 
_api_CreateDirectoryExW(self, return_value, arguments, flags) source code
 
_api_RemoveDirectoryA(self, return_value, arguments, flags) source code
 
_api_RemoveDirectoryW(self, return_value, arguments, flags) source code
 
_api_MoveFileWithProgressW(self, return_value, arguments, flags) source code
 
_api_CopyFileA(self, return_value, arguments, flags) source code
 
_api_CopyFileW(self, return_value, arguments, flags) source code
 
_api_CopyFileExW(self, return_value, arguments, flags) source code
 
_api_DeleteFileA(self, return_value, arguments, flags) source code
 
_api_DeleteFileW(self, return_value, arguments, flags) source code
 
_api_NtDeleteFile(self, return_value, arguments, flags) source code
 
_api_FindFirstFileExA(self, return_value, arguments, flags) source code
 
_api_FindFirstFileExW(self, return_value, arguments, flags) source code
 
_api_LdrLoadDll(self, return_value, arguments, flags) source code
 
_api_NtCreateFile(self, return_value, arguments, flags) source code
 
_api_NtOpenFile(self, return_value, arguments, flags) source code
 
_api_NtReadFile(self, return_value, arguments, flags) source code
 
_api_NtWriteFile(self, return_value, arguments, flags) source code
 
_api_GetFileAttributesW(self, return_value, arguments, flags) source code
 
_api_GetFileAttributesExW(self, return_value, arguments, flags) source code
 
_api_RegOpenKeyExA(self, return_value, arguments, flags) source code
 
_api_RegOpenKeyExW(self, return_value, arguments, flags) source code
 
_api_RegCreateKeyExA(self, return_value, arguments, flags) source code
 
_api_RegCreateKeyExW(self, return_value, arguments, flags) source code
 
_api_RegDeleteKeyA(self, return_value, arguments, flags) source code
 
_api_RegDeleteKeyW(self, return_value, arguments, flags) source code
 
_api_RegDeleteValueA(self, return_value, arguments, flags) source code
 
_api_RegDeleteValueW(self, return_value, arguments, flags) source code
 
_api_NtDeleteValueKey(self, return_value, arguments, flags) source code
 
_api_RegQueryValueExA(self, return_value, arguments, flags) source code
 
_api_RegQueryValueExW(self, return_value, arguments, flags) source code
 
_api_NtQueryValueKey(self, return_value, arguments, flags) source code
 
_api_RegSetValueExA(self, return_value, arguments, flags) source code
 
_api_RegSetValueExW(self, return_value, arguments, flags) source code
 
_api_NtSetValueKey(self, return_value, arguments, flags) source code
 
_api_NtClose(self, return_value, arguments, flags) source code
 
_api_URLDownloadToFileW(self, return_value, arguments, flags) source code
 
_api_InternetConnectA(self, return_value, arguments, flags) source code
 
_api_InternetConnectW(self, return_value, arguments, flags) source code
 
_api_InternetOpenUrlA(self, return_value, arguments, flags) source code
 
_api_InternetOpenUrlW(self, return_value, arguments, flags) source code
 
_api_DnsQuery_A(self, return_value, arguments, flags) source code
 
_api_DnsQuery_W(self, return_value, arguments, flags) source code
 
_api_DnsQuery_UTF8(self, return_value, arguments, flags) source code
 
_api_getaddrinfo(self, return_value, arguments, flags) source code
 
_api_GetAddrInfoW(self, return_value, arguments, flags) source code
 
_api_gethostbyname(self, return_value, arguments, flags) source code
 
_api_connect(self, return_value, arguments, flags) source code
 
_api_NtCreateMutant(self, return_value, arguments, flags) source code
 
_api_ConnectEx(self, return_value, arguments, flags) source code
 
_api_CreateProcessInternalW(self, return_value, arguments, flags) source code
 
_api_ShellExecuteExW(self, return_value, arguments, flags) source code
 
_api_system(self, return_value, arguments, flags) source code
 
_api_IWbemServices_ExecQuery(self, return_value, arguments, flags) source code
 
_api_IWbemServices_ExecQueryAsync(self, return_value, arguments, flags) source code
 
_api_CoCreateInstance(self, return_value, arguments, flags) source code
 
_api_CoCreateInstanceEx(self, return_value, arguments, flags) source code
 
_api_CoGetClassObject(self, return_value, arguments, flags) source code
 
_api_Ssl3GenerateKeyMaterial(self, return_value, arguments, flags) source code
 
_api_PRF(self, return_value, arguments, flags) source code

Inherited from object: __delattr__, __format__, __getattribute__, __hash__, __new__, __reduce__, __reduce_ex__, __repr__, __setattr__, __sizeof__, __str__, __subclasshook__

Properties [hide private]

Inherited from object: __class__

Method Details [hide private]

__init__(self)
(Constructor)

source code 

x.__init__(...) initializes x; see help(type(x)) for signature

Overrides: object.__init__
(inherited documentation)