mirror of
https://github.com/CheckPointSW/InviZzzible
synced 2026-06-08 10:35:43 +00:00
010106480d
Generic: BigRamAlloc has been added - tries to allocate big amount of RAM Generic: UserInputActivity has been added - evasion which utilizes `GetLastInputInfo` API function Generic: DiskEnum Registry Key chech has been added - checks `System\CurrentControlSet\Services\Disk\Enum` reg key for value `0`=`*virtual` Generic: Sandbox-like filename check has been added - checks if current file has any of the following patterns in its path: `C:\SELF.EXE`, `.*self\.*`, `.*sample.*`, `.*sandbox.*`, `.*virus.*`, `.*malware.*` Generic: Processes of AV and research tools check has been added - checks if any of the following processes are running: `avgui.exe`, `avastsvc.exe`, `avastui.exe`, `procmon.exe`, `procmon64.exe`, `procexp.exe`, `procexp64.exe`, `ollydbg.exe`, `windbg.exe`, `avp.exe`, `bdagent.exe`, `bdwtxag.exe`, `dwengine.exe` Generic: Max Processes number check has been added (disabled) Generic: Process with a long name check has been added Hyper-V: CPU HypervisorID check has been added Parallels: CPU HypervisorID check has been added QEMU: QEMU DiskEnum Registry Key has been added Sandboxie: Injected sbiedll module check has been added VMware: VMWare DiskEnum Registry Key check has been added Xen: CPU VendorID check has been added Xen: CPU HypervisorID check has been added Xen: DiskEnum Registry Key check has been added Some build warnings have been fixed
114 lines
2.4 KiB
C++
114 lines
2.4 KiB
C++
#ifndef _JSON_H
|
|
#define _JSON_H
|
|
|
|
#include <boost/property_tree/ptree.hpp>
|
|
#include <boost/property_tree/json_parser.hpp>
|
|
#include <boost/foreach.hpp>
|
|
#include <type_traits>
|
|
#include <sstream>
|
|
#include "helper.h"
|
|
|
|
#include <iostream>
|
|
|
|
namespace pt = boost::property_tree;
|
|
|
|
// tiny json implementation
|
|
class json_tiny {
|
|
pt::ptree root; // root of JSON object
|
|
|
|
public:
|
|
json_tiny() {}
|
|
json_tiny(const pt::ptree &_root) : root(_root) {}
|
|
virtual ~json_tiny() {}
|
|
|
|
static json_tiny* load(const char *pfn);
|
|
static json_tiny* load(std::stringstream &ss);
|
|
static bool dump(const json_tiny &, const char *pfn);
|
|
|
|
template <typename T>
|
|
const T get(const std::string &field, const T &_def) const {
|
|
try {
|
|
return _get<T>(field);
|
|
}
|
|
catch (const pt::ptree_bad_path &) {
|
|
return _def;
|
|
}
|
|
}
|
|
|
|
template <>
|
|
const pt::ptree get(const std::string &field, const pt::ptree &_def) const {
|
|
try {
|
|
return _get_child(field);
|
|
}
|
|
catch (const pt::ptree_bad_path &) {
|
|
return _def;
|
|
}
|
|
}
|
|
|
|
/*
|
|
template <typename T>
|
|
const std::list<T> get_array(const std::string &field) const {
|
|
std::list<T> jl;
|
|
|
|
BOOST_FOREACH(const pt::ptree::value_type &obj, root) {
|
|
jl.push_back(obj.second.data());
|
|
}
|
|
|
|
return jl;
|
|
}
|
|
*/
|
|
|
|
const std::list<std::string> get_entries(const std::string &field) const {
|
|
std::string fe = get<std::string>(field, "");
|
|
if (fe.empty())
|
|
return get_array(field);
|
|
|
|
return { fe };
|
|
}
|
|
|
|
const std::list<std::string> get_array(const std::string &field) const {
|
|
std::list<std::string> jl;
|
|
pt::ptree r;
|
|
try {
|
|
r = root.get_child(field);
|
|
}
|
|
catch (const pt::ptree_bad_path &) {
|
|
return jl;
|
|
}
|
|
|
|
BOOST_FOREACH(const pt::ptree::value_type &obj, r) {
|
|
jl.push_back(obj.second.data());
|
|
}
|
|
|
|
return jl;
|
|
}
|
|
|
|
template <typename T>
|
|
const T operator[](const std::string &) const {
|
|
return _get(field);
|
|
}
|
|
|
|
const std::list<std::pair<std::string, json_tiny>> get_objects(const std::string &type_key, const std::string &type_value) const {
|
|
std::list<std::pair<std::string, json_tiny>> jl;
|
|
BOOST_FOREACH(const pt::ptree::value_type &obj, root) {
|
|
if (obj.second.get<std::string>(type_key, "") == type_value) {
|
|
jl.push_back(std::pair<std::string, json_tiny>(obj.first, obj.second));
|
|
}
|
|
}
|
|
|
|
return jl;
|
|
}
|
|
|
|
private:
|
|
template <typename T>
|
|
const T _get(const std::string &field) const {
|
|
return root.get<T>(field);
|
|
}
|
|
|
|
const pt::ptree _get_child(const std::string &field) const {
|
|
return root.get_child(field);
|
|
}
|
|
};
|
|
|
|
#endif // ! _JSON_H
|