volatility3.plugins.linux.malware package
All core linux malware plugins.
These modules should only be imported from volatility3.plugins NOT volatility3.framework.plugins
Submodules
- volatility3.plugins.linux.malware.check_afinfo module
Check_afinfoCheck_afinfo.build_configuration()Check_afinfo.check_afinfo()Check_afinfo.configCheck_afinfo.config_pathCheck_afinfo.contextCheck_afinfo.get_requirements()Check_afinfo.make_subconfig()Check_afinfo.openCheck_afinfo.run()Check_afinfo.set_open_method()Check_afinfo.unsatisfied()Check_afinfo.version
- volatility3.plugins.linux.malware.check_creds module
- volatility3.plugins.linux.malware.check_idt module
- volatility3.plugins.linux.malware.check_modules module
Check_modulesCheck_modules.build_configuration()Check_modules.compare_kset_and_lsmod()Check_modules.configCheck_modules.config_pathCheck_modules.contextCheck_modules.get_kset_modules()Check_modules.get_requirements()Check_modules.implementation()Check_modules.make_subconfig()Check_modules.openCheck_modules.run()Check_modules.set_open_method()Check_modules.unsatisfied()Check_modules.version
- volatility3.plugins.linux.malware.check_syscall module
- volatility3.plugins.linux.malware.hidden_modules module
Hidden_modulesHidden_modules.build_configuration()Hidden_modules.configHidden_modules.config_pathHidden_modules.contextHidden_modules.find_hidden_modules()Hidden_modules.get_hidden_modules()Hidden_modules.get_lsmod_module_addresses()Hidden_modules.get_modules_memory_boundaries()Hidden_modules.get_requirements()Hidden_modules.implementation()Hidden_modules.make_subconfig()Hidden_modules.openHidden_modules.run()Hidden_modules.set_open_method()Hidden_modules.unsatisfied()Hidden_modules.version
- volatility3.plugins.linux.malware.keyboard_notifiers module
Keyboard_notifiersKeyboard_notifiers.build_configuration()Keyboard_notifiers.configKeyboard_notifiers.config_pathKeyboard_notifiers.contextKeyboard_notifiers.get_requirements()Keyboard_notifiers.make_subconfig()Keyboard_notifiers.openKeyboard_notifiers.run()Keyboard_notifiers.set_open_method()Keyboard_notifiers.unsatisfied()Keyboard_notifiers.version
- volatility3.plugins.linux.malware.malfind module
MalfindMaliciousFlagsMaliciousFlags.RWXMaliciousFlags.RXMaliciousFlags.X_DIRTYMaliciousFlags.as_integer_ratio()MaliciousFlags.bit_count()MaliciousFlags.bit_length()MaliciousFlags.conjugate()MaliciousFlags.denominatorMaliciousFlags.from_bytes()MaliciousFlags.imagMaliciousFlags.numeratorMaliciousFlags.realMaliciousFlags.to_bytes()
- volatility3.plugins.linux.malware.modxview module
ModxviewModxview.build_configuration()Modxview.configModxview.config_pathModxview.contextModxview.flatten_run_modules_results()Modxview.get_requirements()Modxview.make_subconfig()Modxview.openModxview.run()Modxview.run_modules_scanners()Modxview.set_open_method()Modxview.unsatisfied()Modxview.version
- volatility3.plugins.linux.malware.netfilter module
AbstractNetfilterAbstractNetfilter.NF_MAX_HOOKSAbstractNetfilter.PROTO_HOOKSAbstractNetfilter.build_nf_hook_ops_array()AbstractNetfilter.get_hook_ops()AbstractNetfilter.get_hooks_container()AbstractNetfilter.get_member_type()AbstractNetfilter.get_module_name_for_address()AbstractNetfilter.get_net_namespaces()AbstractNetfilter.get_symbol_fullname()AbstractNetfilter.run_all()AbstractNetfilter.subscribed_protocols()AbstractNetfilter.symtab_checks()
AbstractNetfilterNetDevAbstractNetfilterNetDev.NF_MAX_HOOKSAbstractNetfilterNetDev.PROTO_HOOKSAbstractNetfilterNetDev.build_nf_hook_ops_array()AbstractNetfilterNetDev.get_hook_ops()AbstractNetfilterNetDev.get_hooks_container()AbstractNetfilterNetDev.get_member_type()AbstractNetfilterNetDev.get_module_name_for_address()AbstractNetfilterNetDev.get_net_namespaces()AbstractNetfilterNetDev.get_symbol_fullname()AbstractNetfilterNetDev.run_all()AbstractNetfilterNetDev.subscribed_protocols()AbstractNetfilterNetDev.symtab_checks()
NetfilterNetfilterImp_4_14_to_4_16NetfilterImp_4_14_to_4_16.NF_MAX_HOOKSNetfilterImp_4_14_to_4_16.PROTO_HOOKSNetfilterImp_4_14_to_4_16.build_nf_hook_ops_array()NetfilterImp_4_14_to_4_16.get_hook_ops()NetfilterImp_4_14_to_4_16.get_hooks_container()NetfilterImp_4_14_to_4_16.get_member_type()NetfilterImp_4_14_to_4_16.get_module_name_for_address()NetfilterImp_4_14_to_4_16.get_net_namespaces()NetfilterImp_4_14_to_4_16.get_nf_hook_entries()NetfilterImp_4_14_to_4_16.get_symbol_fullname()NetfilterImp_4_14_to_4_16.run_all()NetfilterImp_4_14_to_4_16.subscribed_protocols()NetfilterImp_4_14_to_4_16.symtab_checks()
NetfilterImp_4_16_to_latestNetfilterImp_4_16_to_latest.NF_MAX_HOOKSNetfilterImp_4_16_to_latest.PROTO_HOOKSNetfilterImp_4_16_to_latest.build_nf_hook_ops_array()NetfilterImp_4_16_to_latest.get_hook_ops()NetfilterImp_4_16_to_latest.get_hooks_container()NetfilterImp_4_16_to_latest.get_member_type()NetfilterImp_4_16_to_latest.get_module_name_for_address()NetfilterImp_4_16_to_latest.get_net_namespaces()NetfilterImp_4_16_to_latest.get_nf_hook_entries()NetfilterImp_4_16_to_latest.get_symbol_fullname()NetfilterImp_4_16_to_latest.run_all()NetfilterImp_4_16_to_latest.subscribed_protocols()NetfilterImp_4_16_to_latest.symtab_checks()
NetfilterImp_4_3_to_4_9NetfilterImp_4_3_to_4_9.NF_MAX_HOOKSNetfilterImp_4_3_to_4_9.PROTO_HOOKSNetfilterImp_4_3_to_4_9.build_nf_hook_ops_array()NetfilterImp_4_3_to_4_9.get_hook_ops()NetfilterImp_4_3_to_4_9.get_hooks_container()NetfilterImp_4_3_to_4_9.get_member_type()NetfilterImp_4_3_to_4_9.get_module_name_for_address()NetfilterImp_4_3_to_4_9.get_net_namespaces()NetfilterImp_4_3_to_4_9.get_symbol_fullname()NetfilterImp_4_3_to_4_9.run_all()NetfilterImp_4_3_to_4_9.subscribed_protocols()NetfilterImp_4_3_to_4_9.symtab_checks()
NetfilterImp_4_9_to_4_14NetfilterImp_4_9_to_4_14.NF_MAX_HOOKSNetfilterImp_4_9_to_4_14.PROTO_HOOKSNetfilterImp_4_9_to_4_14.build_nf_hook_ops_array()NetfilterImp_4_9_to_4_14.get_hook_ops()NetfilterImp_4_9_to_4_14.get_hooks_container()NetfilterImp_4_9_to_4_14.get_member_type()NetfilterImp_4_9_to_4_14.get_module_name_for_address()NetfilterImp_4_9_to_4_14.get_net_namespaces()NetfilterImp_4_9_to_4_14.get_symbol_fullname()NetfilterImp_4_9_to_4_14.run_all()NetfilterImp_4_9_to_4_14.subscribed_protocols()NetfilterImp_4_9_to_4_14.symtab_checks()
NetfilterImp_to_4_3NetfilterImp_to_4_3.NF_MAX_HOOKSNetfilterImp_to_4_3.PROTO_HOOKSNetfilterImp_to_4_3.build_nf_hook_ops_array()NetfilterImp_to_4_3.get_hook_ops()NetfilterImp_to_4_3.get_hooks_container()NetfilterImp_to_4_3.get_member_type()NetfilterImp_to_4_3.get_module_name_for_address()NetfilterImp_to_4_3.get_net_namespaces()NetfilterImp_to_4_3.get_symbol_fullname()NetfilterImp_to_4_3.run_all()NetfilterImp_to_4_3.subscribed_protocols()NetfilterImp_to_4_3.symtab_checks()
NetfilterNetDevImp_4_14_to_latestNetfilterNetDevImp_4_14_to_latest.NF_MAX_HOOKSNetfilterNetDevImp_4_14_to_latest.PROTO_HOOKSNetfilterNetDevImp_4_14_to_latest.build_nf_hook_ops_array()NetfilterNetDevImp_4_14_to_latest.get_hook_ops()NetfilterNetDevImp_4_14_to_latest.get_hooks_container()NetfilterNetDevImp_4_14_to_latest.get_member_type()NetfilterNetDevImp_4_14_to_latest.get_module_name_for_address()NetfilterNetDevImp_4_14_to_latest.get_net_namespaces()NetfilterNetDevImp_4_14_to_latest.get_symbol_fullname()NetfilterNetDevImp_4_14_to_latest.run_all()NetfilterNetDevImp_4_14_to_latest.subscribed_protocols()NetfilterNetDevImp_4_14_to_latest.symtab_checks()
NetfilterNetDevImp_4_2_to_4_9NetfilterNetDevImp_4_2_to_4_9.NF_MAX_HOOKSNetfilterNetDevImp_4_2_to_4_9.PROTO_HOOKSNetfilterNetDevImp_4_2_to_4_9.build_nf_hook_ops_array()NetfilterNetDevImp_4_2_to_4_9.get_hook_ops()NetfilterNetDevImp_4_2_to_4_9.get_hooks_container()NetfilterNetDevImp_4_2_to_4_9.get_member_type()NetfilterNetDevImp_4_2_to_4_9.get_module_name_for_address()NetfilterNetDevImp_4_2_to_4_9.get_net_namespaces()NetfilterNetDevImp_4_2_to_4_9.get_symbol_fullname()NetfilterNetDevImp_4_2_to_4_9.run_all()NetfilterNetDevImp_4_2_to_4_9.subscribed_protocols()NetfilterNetDevImp_4_2_to_4_9.symtab_checks()
NetfilterNetDevImp_4_9_to_4_14NetfilterNetDevImp_4_9_to_4_14.NF_MAX_HOOKSNetfilterNetDevImp_4_9_to_4_14.PROTO_HOOKSNetfilterNetDevImp_4_9_to_4_14.build_nf_hook_ops_array()NetfilterNetDevImp_4_9_to_4_14.get_hook_ops()NetfilterNetDevImp_4_9_to_4_14.get_hooks_container()NetfilterNetDevImp_4_9_to_4_14.get_member_type()NetfilterNetDevImp_4_9_to_4_14.get_module_name_for_address()NetfilterNetDevImp_4_9_to_4_14.get_net_namespaces()NetfilterNetDevImp_4_9_to_4_14.get_symbol_fullname()NetfilterNetDevImp_4_9_to_4_14.run_all()NetfilterNetDevImp_4_9_to_4_14.subscribed_protocols()NetfilterNetDevImp_4_9_to_4_14.symtab_checks()
Proto
- volatility3.plugins.linux.malware.process_spoofing module
ProcessSpoofingProcessSpoofing.build_configuration()ProcessSpoofing.configProcessSpoofing.config_pathProcessSpoofing.contextProcessSpoofing.extract_process_names()ProcessSpoofing.get_cmdline_basename()ProcessSpoofing.get_comm()ProcessSpoofing.get_executable_path()ProcessSpoofing.get_requirements()ProcessSpoofing.make_subconfig()ProcessSpoofing.openProcessSpoofing.run()ProcessSpoofing.set_open_method()ProcessSpoofing.unsatisfied()ProcessSpoofing.version
- volatility3.plugins.linux.malware.tty_check module