hakril
ed0099fd57
PFW symbols engine can now pull dbghelp.dll path from env var PFW_DBGHELP_PATH
2020-05-05 16:29:02 +02:00
hakril
466d94c03c
Fixed broken basestring for py3 compatibility (see issue #15 )
2020-05-02 23:12:25 +02:00
hakril
578b4d9193
Update generated def + documentation
2020-03-29 22:14:29 +02:00
hakril
f63f7f308a
Some quick and dirty fix for debugger/breakpoint in python3
2020-03-29 21:41:48 +02:00
hakril
c691d8eb84
Added EvtQuery.seek() + IsDebuggerPresent API for sample purpose
2020-03-19 10:33:12 +01:00
hakril
91e6ef824c
Added EventLog.date for simplicity of use
2020-03-16 13:19:03 +01:00
hakril
546818f91b
Added a sample for windows.debug.FunctionCallBP : change_function_ret_value.py
2020-03-10 23:59:50 +01:00
hakril
fb23ad2838
Fix syswow64 32<->64 for python3-23b
2020-03-10 21:03:59 +01:00
hakril
7921e74647
Fixed a GC issue with system.modules + added deprecation warning to utils.get_kernel_modules()
2020-03-10 20:50:04 +01:00
hakril
02b2ba13f9
Added a poc for a WinFile object
2020-02-13 23:24:37 +01:00
hakril
92df7eaee0
New generated_def py3 ready \o/ PFW should be ready for py3 testing
2020-02-13 23:18:47 +01:00
hakril
9f69b1cefa
Adapted some stuff in security.py for py3
2020-02-13 23:17:43 +01:00
hakril
66382b89f7
Some more py3 compat fix + few feature in POC
2020-02-13 22:30:46 +01:00
hakril
4dc71b0449
Added some flags & improved explain()
2020-02-13 22:23:55 +01:00
hakril
4d3b3e18ad
Lot of small py3 compat fix
2020-02-13 22:23:20 +01:00
hakril
f403856e26
Debugger test pass on py3
2020-02-08 00:15:41 +01:00
hakril
6a74c83670
test_process pass for python3 + added some pe_parse test
2020-02-07 23:06:26 +01:00
hakril
889de363ca
windows.injection now handle injection of py3 code !
2020-02-06 00:03:10 +01:00
hakril
bac3dcb55b
Fix simple_x64 REX for python3
2020-02-05 23:57:34 +01:00
hakril
2f778b69f9
windows.pipe.create now accept a custom security descriptor as parameter
2020-02-03 21:42:34 +01:00
hakril
2fddd82f00
Adding pycompat.py for py2/py3 work in progress
2020-02-02 18:18:56 +01:00
hakril
46197e763a
Fixed windows.winproxy.resolve (corresponding test already exist)
2020-02-02 18:17:36 +01:00
hakril
f2a6489463
Added mov REG/SEGREG in simple_x86 + fix a bug in syswow64 on AMD do to a processor bug (Issue10)
2020-02-02 17:49:42 +01:00
hakril
2e1043ead4
Added some code to play with extended attributes
2020-01-26 16:02:38 +01:00
hakril
b490130585
Aded new generated ctypes_generation
2020-01-26 15:55:21 +01:00
hakril
d20083c57c
windows.crypto.sign accept sin algo as parameter
2020-01-26 15:51:03 +01:00
hakril
b971fa5faf
Added some functions to winproxy
2020-01-17 21:11:24 +01:00
hakril
c589a41902
[WIP] saving POC of symbol
2020-01-17 21:07:35 +01:00
hakril
7638080ee4
Added new service API allowing to find service by name easily
2019-11-14 13:31:20 +01:00
hakril
6f55d2e48f
Fix a bug in debugger when detaching after a Ctrl+c during a BP
2019-10-19 00:39:03 +02:00
1orenz0
5b55d4d693
[event_log] Add some more format type to support
2019-10-14 22:03:49 +02:00
1orenz0
4f92323abf
[event log] export message_id instead of message_name
...
It's more consistent with the other classes
2019-10-14 22:03:49 +02:00
1orenz0
6dd314659d
[event log] adding event channel metadata message ID
2019-10-14 22:03:49 +02:00
1orenz0
adb7d3b63a
[event log] adding event metadata
2019-10-14 22:03:49 +02:00
1orenz0
b5371ddf33
[event log] still adding publisher metadata
2019-10-14 22:03:49 +02:00
1orenz0
4495eca6d0
[event log] add some more metadata
2019-10-14 22:03:49 +02:00
1orenz0
df28515b97
[event log] Expose message filename
2019-10-14 22:03:49 +02:00
1orenz0
6374f91fef
[event log] Expose channel metadatas
2019-10-14 22:03:49 +02:00
1orenz0
6125a1fb15
[event_trace] Add a way to pass a Python object to an ETW trace's
...
context
It may be useful to pass a python object (e.g. class) to the ETW
processing callback. The ETW tracing API allows the user to fill out a
"Context" field with a pointer value that will be passed to the event
being sent, the rest is ctypes magic for wrapping the python object
into a native pointer value.
2019-10-14 22:03:49 +02:00
1orenz0
bfeb2e6dec
[event_log] Configure an ETW trace to listen on specific keywords
...
By default EnableTrace will listen with a "KeywordsAny" value of
0xffffffff. Some event log providers send events with keywords over
0x100000000, so we need a mecanism to filter on thoses keywords.
2019-10-14 22:03:49 +02:00
1orenz0
536a60c040
[event log] Expose event keywords and publisher guid
...
Accessing the publisher guid is useful to setup an ETW trace, and we
need to know event keywords in order to activate the ETW session on the
correct "channels".
2019-10-14 22:03:49 +02:00
hakril
05ee89de81
Adding some service related definition + added services specific access right to security.py
2019-10-14 21:52:54 +02:00
hakril
80799fe411
Working on improving the Evt related api
2019-10-14 21:52:02 +02:00
hakril
30b05d25f1
Improved MultipleInstr capabilities + fix a bug in x64 that failed to recognize 32b register name not uppercase
2019-09-20 16:18:16 +02:00
hakril
6bd45e8503
Added regkey.empty() based on RegDeleteTreeW
2019-08-13 14:57:56 +02:00
hakril
168783af9d
Improved CryptMsg API with some more properties
2019-08-12 13:50:08 +02:00
hakril
b9fe4d19e5
Added ControlService + service.stop() + service.start() accept arguments
2019-08-08 10:28:22 +02:00
hakril
6fcba46739
Added <Raw> pseudo instruction to both assemblers + corresponding test
2019-08-07 17:42:56 +02:00
hakril
960838ae3c
handle code now use gdef + added some handle tests
2019-08-07 17:25:36 +02:00
hakril
8a32e00f68
Handle documented key type and unkown one + add code to handle badly encoded values (REG_MULTI_SZ notably)
2019-08-07 14:48:26 +02:00