diff --git a/README.md b/README.md index b439b3b..21563af 100644 --- a/README.md +++ b/README.md @@ -31,6 +31,37 @@ All those operations are also available for the `current_process`. You can also make some operation on threads (suspend/resume/wait/get(or set) context/ kill) +```python +>>> import windows +>>> windows.current_process.bitness +32 +>>> calc = [p for p in windows.system.processes if p.name == "calc.exe"][0] +>>> calc + +>>> calc.bitness +64 +>>> calc.peb.modules[:3] +[, , ] +>>> k32 = calc.peb.modules[2] +>>> hex(k32.pe.exports["CreateFileW"]) +'0x7ffee6761550L' +>>> calc.threads[0] + +>>> hex(calc.threads[0].context.Rip) +'0x7ffee68b54b0L' +>>> calc.execute_python("import os") +True +>>> calc.execute_python("exit(os.getpid() + 1)") +# execute_python raise if process died +Traceback (most recent call last): +... +ValueError: Unknown exit code 0xc000004bL +>>> calc + +>>> calc.exit_code +6961L +``` + ### IAT Hook @@ -50,14 +81,59 @@ To make the barrier between `native` and `Python` code, PythonForWindows allows you to create native function callable from Python (thanks `ctypes`) and also embed a simple x86/x64 assembler. +```python +>>> import windows.native_exec.simple_x86 as x86 +>>> code = x86.MultipleInstr() +>>> code += x86.Mov("EAX", 41) +>>> code += x86.Inc("EAX") +>>> code += x86.Ret() +>>> code.get_code() +'\xc7\xc0)\x00\x00\x00@\xc3' +# Create a function that takes no parameters and return an uint +>>> f = windows.native_exec.create_function(code.get_code(), [ctypes.c_uint]) +>>> f() +42L +``` -## Other stuff +### Wintrust -Some code are just explorations and need improvements like: +To easily script some signature check script, PythonForWindows implements some wrapper functions around ``wintrust.dll`` -- Wintrust -- WMI -- Exception +```python +>>> import windows.wintrust +>>> windows.wintrust.is_signed(r"C:\Windows\system32\ntdll.dll") +True +>>> windows.wintrust.is_signed(r"C:\Windows\system32\python27.dll") +False +>>> windows.wintrust.full_signature_information(r"C:\Windows\system32\ntdll.dll") +SignatureData(signed=True, + catalog=u'C:\\Windows\\system32\\CatRoot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Package_35_for_KB3128650~31bf3856ad364e35~amd64~~6.3.1.2.cat', + catalogsigned=True, additionalinfo=0L) +>>> windows.wintrust.full_signature_information(r"C:\Windows\system32\python27.dll") +SignatureData(signed=False, catalog=None, catalogsigned=False, additionalinfo=TRUST_E_NOSIGNATURE(0x800b0100L)) +``` + +### WMI + +To extract/play with even more information about the system, PythonForWindows is able to perform WMI request. + +```python +>>> import windows +>>> windows.system.wmi.select +> +>>> windows.system.wmi.select("Win32_Process", ["Name", "Handle"])[:4] +[{'Handle': u'0', 'Name': u'System Idle Process'}, {'Handle': u'4', 'Name': u'System'}, {'Handle': u'412', 'Name': u'smss.exe'}, {'Handle': u'528', 'Name': u'csrss.exe'}] +# Get WMI data for current process +>>> wmi_cp = [p for p in windows.system.wmi.select("Win32_Process") if int(p["Handle"]) == windows.current_process.pid][0] +>>> wmi_cp["CommandLine"], wmi_cp["HandleCount"] +(u'"C:\\Python27\\python.exe"', 227) +``` + +### Other stuff (see doc / samples) + +- Registry +- Network +- Services - COM